跳到正文
原文
Permission Protocol · AI Agent Incident Tracker·· 2026/04/22精选AI 评分80

Bitwarden CLI 遭 Shai-Hulud 供应链攻击,定向窃取 Claude Code、Cursor、Codex CLI 的 API Key

原文标题:Bitwarden CLI 'Shai-Hulud' Supply Chain Attack Targeted Claude Code, Cursor, Codex CLI API Keys: 334 Developers Exposed

AI 导读

攻击者劫持 Bitwarden 的 CI/CD 流水线,向 npm 发布恶意 @bitwarden/[email protected],在 2026 年 4 月 22 日 5:57–7:30 PM ET 的 90 分钟窗口内被 334 名开发者安装。

推荐理由

复盘了恶意 npm 包如何定向窃取 AI 编程工具凭证,并给出 90 分钟窗口与影响范围等可核查细节。

正文

Bitwarden CLI 'Shai-Hulud' Supply Chain Attack Targeted Claude Code, Cursor, Codex CLI API Keys: 334 Developers Exposed

Attackers hijacked Bitwarden's CI/CD pipeline and published malicious @bitwarden/cli to npm. Malware explicitly scanned for Claude Code, Cursor, Codex CLI, and Aider API keys. 334 developers exposed in a 90-minute window on April 22, 2026.

Malicious @bitwarden/[email protected] published to npm after CI/CD pipeline hijack. Malware scanned .claude/, .cursor/, and Aider config paths for API keys, exfiltrating them via AES-256-GCM encryption to an attacker-controlled domain impersonating Checkmarx.

334 developers had AI API keys (Claude Code, Cursor, Codex CLI, Aider), GitHub tokens, and AWS/GCP credentials exfiltrated. Each compromised developer is a potential pivot point into every CI/CD pipeline and repository they can access.

  1. 2026-04-22

    Attackers hijack Bitwarden's CI/CD pipeline and publish malicious @bitwarden/[email protected] to npm.

  2. 2026-04-22

    Package available 5:57–7:30 PM ET (90-minute window). 334 developers install the malicious version.

  3. 2026-04-22

    Malware scans .claude/, .cursor/, Aider configs; exfiltrates AI API keys, GitHub tokens, AWS/GCP credentials via AES-256-GCM.

  4. 2026-04-22

    Bitwarden detects and removes malicious package. Clean version published.

  5. 2026-04-23

    Palo Alto Networks, Endor Labs, and Sophos publish attribution to the Shai-Hulud campaign — linked to prior supply chain operations.

  • The malware explicitly targeted .claude/, .cursor/, and Aider config directories — AI developer tool credentials are now a first-class supply chain target category.
  • 90-minute availability window is consistent with organized supply chain actors: publish during off-hours, collect installs, remove before major detection systems fire.
  • AES-256-GCM exfiltration to a Checkmarx-impersonating domain made initial triage harder — traffic blends with expected security tool callbacks.
  • 334 exposed developers each represent a pivot into their downstream CI/CD pipelines — the blast radius is multiplicative, not linear.
  • Shai-Hulud campaign linkage indicates an organized threat actor with experience specifically in npm supply chain operations.

来源:Permission Protocol · AI Agent Incident Tracker · permissionprotocol.com