The Bitwarden security team identified and contained a malicious package that was briefly distributed through the npm delivery path for @bitwarden/cli@2026.4.0 between 5:57 PM and 7:30 PM (ET) on April 22, 2026, in connection with a broader Checkmarx supply chain incident. Was I affected? If you use the Bitwarden command line interface and deploy using NPM, and downloaded the CLI between 5:57p ET and 7:30p ET on April 22, 2026, you may be affected. See remediation steps below. If you do not u...
No. Offline password managers are also suspectible to supply chain risk.
So is everything else. But KeePass has been a highly reputable password manager for close to 20 years now.
I don’t think it uses npm though, that’s got to count for something
deleted by creator