Logo
npm

@bitwardne/cli@1.0.1

Vulnerability report · Last retrieved from osv.dev October 8, 2026 at 9:46 PM UTC

Malicious

OSV ID

MAL-2026-17693

Ecosystem

npm

Summary

package.json declares a preinstall lifecycle script of the form 'curl -L <url> | node', which fetches remote content and executes it in Node at npm install time. In this published version the URL slot is empty so the command fails as shipped, but the script shape is a canonical install-time remote-code-execution dropper that fires automatically on npm install. The package is published under the @bitwardne scope — a one-character variation of the Bitwarden brand — while the shipped source is a verbatim copy of the unrelated 'cli' option-parser library by Chris O'Hara (homepage node-js-libs/cli), with no legitimate connection between the scope name and the vendored code.

Source: amazon-inspector (cf7d0b3168a3a56cb6208688970e6109a964ccfb99a97fe7061d57e007b67ca6)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.