Bitwarden CLI compromised (News)

比特卫门CLI被入侵(新闻)

The Changelog: Software Development, Open Source

2026-04-29

8 分钟
PDF

单集简介 ...

Bitwarden's CLI got hit by the Checkmarx supply-chain campaign, TypeScript 7.0 beta lands with the Go-rewritten compiler running ~10x faster than 6.0, and pgBackRest lost its maintainer of thirteen years leaving anyone running production Postgres with a real dependency-trust task this week. We've also got Ubuntu 26.04 LTS shipping with TPM-backed full-disk encryption, and Matz dropping Spinel as an AOT path that takes Ruby to native binaries. This week was a good reminder that the tools we depend on are all moving at once. Security, performance, and maintenance aren't isolated threads.
更多

单集文稿 ...

  • What's up, friends?

  • Adam here.

  • This is Change Talk News for the week of April 27th, 2026.

  • Fresh off the press, literally hours old at this point.

  • Warp is now open source.

  • Yes, your favorite terminal, and mine too, besides Ghosty, of course, is now open source.

  • Years ago, we had Zach on the pod and pressured him.

  • Highly suggested, I should say, that Warp be open source.

  • And the day is finally here.

  • They are now open source.

  • The primary reason is, quote, that we think we can ship a better warp more quickly if we open source

  • and work with our community, end quote.

  • Big congrats, Zach.

  • I'm excited.

  • Are you excited?

  • Okay, let's get into the news.

  • Bitwarden CLI has been compromised.

  • Yes, Bitwarden's official command line tool got hit last Thursday.

  • Our friends at Socket are on the beat.

  • They flagged a malicious CLI published to NPM as part of the same checkmarks themed supply chain campaign