- cross-posted to:
- cybersecurity@sh.itjust.works
- cross-posted to:
- cybersecurity@sh.itjust.works
You must log in or # to comment.
Eli5 please.
yesterday, for about 1h30min (starting at 5:57pm ET / 9:57pm UTC) anyone installing the latest version of the command line interface of bitwarden was installing malware.
the malware steals GitHub/npm tokens, .ssh, .env, shell history, GitHub Actions and cloud secrets, then exfiltrates the data to private domains and as GitHub commits
there’s no evidence that end user vault data was accessed or at risk, or that production data or production systems were compromised
So if you use the phone app, or browser extension you are okay?
yes




