

Justin Sun isn’t just any billionaire. He made his money through crypto and he would recognize a crypto scam. Shortly after purchasing a lot of WLF, the SEC suspiciously stopped a lawsuit against him. He may be unhappy with what he got in exchange for his “investment.”





This problem has nothing to do with NPM. Checkmarx was compromised last month, and during that compromise there were malicious VS Code extensions published to Visual Studio Code Marketplace. A Bitwarden developer says that somebody ran one of those malicious extensions, and GitHub API keys were stolen which were used in publishing the malicious CLI package.
It’s probably better that it happened on NPM. If the CLI were only downloadable from the Bitwarden website, it would have likely taken longer for somebody to notice something was wrong.