Socket
Bitwarden CLI Compromise Linked to Ongoing Checkmarx Supply Chain Campaign
Jeffrey Burt | | AI, Bitwarden, Checkmarx, CI/CD Security, GitHub, JFrog Security, MCP, npm repository, OX Security, Shai-Hulud, Socket, StepSecurity, supply chain attack, TeamPCP, Trivy
A compromise of the popular Bitwarden password manager is linked to the ongoing Checkmarx supply chain campaign, with bad actor injecting malicious code in a version of its CLI. However, while there ...
Security Boulevard
An Evolving GlassWorm Malware is Making the Rounds of Code Repositories
Jeffrey Burt | | Aikido Security, GitHub, GlassWorm, Koi Security, MCP servers, npm, Open VSX, PyPI security, Remote Access Trojan (RAT), Socket
The bad actor can now deploy a RAT, is targeting MCP servers, and is finding new ways to move through Open VSX ...
Security Boulevard

