Around 5:00 p.m. CET, we were alerted to the compromise of the Bitwarden/CLI package via https://opensourcemalware.com/npm/@bitwarden/cliThe Jfrog analyses at https://research.jfrog.com/post/bitwarden-cli-hijack/ explain that the data exfiltration is primarily directed to audit[.]checkmarx[.]cx.
