@bitwarden/cli:2026.4.0 infected with malware?

There have been multiple reports that the npm package @bitwarden/cli has been compromised in version 2026.4.0:

Has there been any official confirmation from the Bitwarden team?

I am a volunteer moderator here (i.e., a Bitwarden user, not an employee), so this is not an official confirmation, but I wanted to share with you that mods have received information that Bitwarden has taken action on this and will be making some kind of public announcement. Stay tuned…

This Github comment has the first official response from a Bitwarden rep:

“We verified that a malicious version of CLI was published to NPM as 2026.4.0. We have since deprecated that version and contacted NPM for its removal.”

And now there is a slightly more detailed statement, in a pinned post on the forum:

Closing this topic and encourage people to continue the discussion in the pinned topic @grb linked above.