The Bitwarden CLI was briefly compromised after attackers uploaded a malicious @bitwarden/cli package to npm containing a credential-stealing payload capable of spreading to other projects.
Patching is not enough: applications embedding the insecure library will need to be rebuilt, and affected tokens and cookies ...