Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The Bitwarden NPM package was hit in a supply-chain attack, but the incident did not compromise Bitwarden’s stored vault database or ordinary Bitwarden apps. The affected release was @bitwarden/cli@2026.4.0, distributed through npm for about 93 minutes on April 22, 2026. Risk was concentrated among users and CI systems that installed and ran that release.
Bitwarden said its investigation found no evidence that end-user vault data, production data, or production systems were accessed. The affected distribution path was the npm package for Bitwarden’s command-line interface (CLI), not the browser extension, desktop application, mobile applications, hosted vault service, or self-hosted server. The official Bitwarden incident statement connects the event to a broader Checkmarx supply-chain compromise.
Key takeaways
@bitwarden/cli@2026.4.0was available from npm on April 22, 2026, from 5:57 p.m. to 7:30 p.m. Eastern Time, a window of approximately 93 minutes.- People who used only Bitwarden’s browser extension, desktop app, mobile app, or web vault were not identified by Bitwarden as affected by this incident.
- A developer workstation, CI runner, container, or automation host that installed and executed the malicious CLI release should be treated as potentially compromised until investigated.
- External researchers reported that the package could search files and environment variables for secrets and target GitHub, npm, AWS, Azure, and Google Cloud credentials.
- Bitwarden released CLI
2026.4.1on April 23, 2026; the official release page later listed CLI2026.4.2, released May 20, 2026. - Removing the package or upgrading it does not revoke credentials that the malicious process may already have read.
Am I affected by the Bitwarden NPM package supply-chain attack?
You are potentially affected if you installed or downloaded @bitwarden/cli@2026.4.0 from npm during the April 22, 2026, window and the package ran on a machine or build environment containing credentials, tokens, files, or npm publishing permissions.
| Situation | Initial assessment | Recommended response |
|---|---|---|
| You used only the Bitwarden browser extension, desktop app, mobile app, or web vault. | You were not identified as affected by Bitwarden’s investigation. | No incident-specific CLI cleanup is normally required. Continue using Bitwarden normally and watch for official updates. |
| You use Bitwarden but never installed the CLI. | The affected npm package was not part of your setup. | No incident-specific action is normally required. |
You installed a Bitwarden CLI version other than 2026.4.0. |
The listed malicious release was not installed, although cached artifacts and automated workflows may require separate review. | Check CI logs, lockfiles, package caches, and container history if the installation route is unclear. |
You installed or ran 2026.4.0 between 5:57 p.m. and 7:30 p.m. ET on April 22, 2026. |
Potentially affected. | Contain the environment, preserve evidence, remove the package, rotate accessible credentials, and investigate for propagation. |
| A CI runner or production automation host installed the package during the window. | High-priority potential exposure because automation often holds broad secrets and publishing permissions. | Stop affected jobs, preserve runner and audit evidence, revoke secrets from a clean environment, and inspect repositories, registries, and cloud logs. |
Downloading the package without deliberately running the CLI is not automatically proof of safety. npm installation can involve lifecycle behavior, and the exact risk depends on how npm was configured and what happened in the installation environment. Conversely, a current installation showing a clean version does not prove that an earlier malicious version was never installed or executed.
#1 Best Overall
- Lifetime warranty!
- Small enough to fit on a key ring
- Universal compatibility with HID proximity card readers
- Provides an external number for easy identification and control Can be placed on a key ring for conv
- Supports formats up to 85 bits, with over 137 billion codes
What exactly was compromised?
The compromised component was the npm-distributed package named @bitwarden/cli, specifically version 2026.4.0. The incident concerned a malicious release obtained through npm; it should not be described as a breach of every copy of Bitwarden’s source code or as a compromise of Bitwarden’s password-vault backend.
Bitwarden deprecated the malicious release, revoked compromised access, and issued a replacement. Bitwarden’s clarification said ordinary users were not affected and that its investigation found no evidence of end-user vault-data access. That statement is a report of Bitwarden’s investigation, not an independently provable guarantee about every possible local environment.
| Component or route | Covered by the incident? |
|---|---|
@bitwarden/cli@2026.4.0 from npm |
Yes, during the defined exposure window. |
| Bitwarden browser extension | Not identified as affected. |
| Bitwarden desktop application | Not identified as affected. |
| Bitwarden iOS or Android applications | Not identified as affected. |
| Bitwarden web vault and stored vault database | Bitwarden said it found no evidence of compromise. |
| Bitwarden hosted production systems | Bitwarden said it found no evidence of access or compromise. |
| Native CLI executable downloads | Not the affected npm distribution path; verify downloads and checksums through Bitwarden’s current documentation. |
When was the malicious Bitwarden CLI package available?
The malicious npm release was available on April 22, 2026, from 5:57 p.m. through 7:30 p.m. Eastern Time, for approximately 93 minutes. The precise time zone matters for organizations reviewing CI logs, registry logs, endpoint telemetry, and cloud audit records.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →The short window does not make the event harmless. A package executed on a privileged build runner can expose tokens or publish permissions quickly, even if the package was available for less than two hours. The relevant question is not only how long the release was public, but what the affected process could read and do during execution.
What could the malicious package do?
Bitwarden confirmed that a malicious package was briefly distributed through npm, that the release was deprecated, that compromised access was revoked, and that its investigation found no evidence of access to end-user vault data or production systems. Bitwarden associated the incident with CVE-2026-42994.
Technical details about the payload come from Palo Alto Networks Unit 42 and should be distinguished from Bitwarden’s own confirmed findings. The researchers reported capabilities that included:
- Searching local filesystems for credentials and other secrets.
- Inspecting environment variables, which commonly contain CI tokens, cloud credentials, and deployment secrets.
- Targeting GitHub Actions credentials and other GitHub access material.
- Looking for AWS, Azure, and Google Cloud credentials.
- Attempting to backdoor npm packages that the victim had permission to publish.
- Spreading beyond the initially installed package in a worm-like manner.
Those findings describe what the payload was capable of or designed to attempt. They do not establish that every capability successfully executed on every installation, nor do they prove that every user’s credentials were stolen. Use the Unit 42 npm supply-chain analysis and the Palo Alto Networks technical report for current indicators and technical updates rather than copying indicators from unsourced secondary coverage.
How does the Bitwarden incident fit the Checkmarx campaign?
The Bitwarden incident was part of a broader supply-chain event associated by Bitwarden with a Checkmarx compromise. In broad terms, attackers obtained access connected to software-development or distribution infrastructure, used trusted channels to distribute malicious releases, and caused Bitwarden’s legitimate package name to deliver an unsafe version.
Rank #2
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- A broader compromise affected development or software-distribution infrastructure associated with the campaign.
- Compromised access was used to publish or distribute malicious software through trusted package channels.
- The legitimate
@bitwarden/clinpm package became one of the affected distribution points. - Normal npm installation and developer trust in a familiar package name helped move the payload into workstations and automation environments.
Palo Alto Networks and Unit 42 reported links to TeamPCP or @pcpcats. That is researcher attribution, not a definitive public finding about the identity of every person involved. The evidence supplied here does not establish which individual account, token, or repository was first compromised, so claims more specific than the published attribution should be treated as speculation.
What is CVE-2026-42994?
CVE-2026-42994 is the vulnerability identifier associated with the malicious Bitwarden CLI release. The NIST National Vulnerability Database entry identifies Bitwarden CLI and records different scores under different CVSS versions.
| Scoring context | Score | Rating |
|---|---|---|
| NVD CVSS 3.1 | 9.8 | Critical |
| MITRE-recorded CVSS 4.0 | 8.8 | High |
Different CVSS versions and scoring authorities can produce different numerical ratings. The difference between 9.8 Critical and 8.8 High does not mean the incident is minor; the operational severity still depends on whether the package ran in an environment with valuable credentials, network access, or publishing authority.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →What should affected users do first?
Affected users should contain the environment before assuming that an upgrade alone solves the problem. The sequence below separates preservation, removal, and credential recovery.
1. Stop further execution
- Stop CI/CD jobs that may install or execute the affected package.
- Prevent deployment from affected runners until the runner has been reviewed or rebuilt.
- Disconnect a developer workstation from sensitive build and publishing workflows if there are signs of compromise.
- Do not run the affected CLI again merely to inspect it.
2. Preserve evidence before destroying the environment
Save relevant CI logs, npm logs, package metadata, endpoint telemetry, shell history, process information, container history, registry activity, and cloud audit records before deleting a runner or wiping a workstation. Deleting a compromised runner immediately may remove the evidence needed to determine whether credentials were accessed or packages were modified.
3. Remove the package and clean caches
Bitwarden’s published cleanup guidance includes the following commands:
npm uninstall -g @bitwarden/cli
npm cache clean --force
npm config set ignore-scripts true
ignore-scripts=true is a temporary precaution during cleanup and investigation. npm lifecycle scripts are used by legitimate packages too, so leaving this setting enabled permanently can break other installations or hide required build steps. Record the setting and restore the organization’s intended npm policy after cleanup.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRemove the affected version from global and project-level package locations, npm caches, Docker layers, artifact repositories, build outputs, and disposable runner images. Rebuild images from a known-clean base instead of assuming that deleting the top-level package removes a cached malicious layer.
Rank #3
- Note: These are 125kHz key fobs (tags). If you want to add them to your lock system, please ensure that your system uses the same frequency of unencrypted 125kHz. Not compatible with other frequencies like 13.56MHz. For example, they don't work for Tuya or TTLock smart locks. Not work for encrypted systems.
- Compatible with other universal 125kHz tags like EM4100/4102. Not compatible with encrypted tags like HID, Indala, Cobra, APCiK, Paradox, Kaba, Isonas, etc.
- Read only. Not rewritable. You cannot re-program them. Each key fob is already pre-programmed with a unique ID number. The 10-digit number is engraved on the tag casing.
- Suitable for 125kHz RFID proximity access control system and ID management system. For example, add it to your RFID door lock if applicable.
- Approx. Size: 1.4*1.1*0.2 inch. Casing Material: ABS Plastic. Package includes 100 PCS.
4. Install a clean release
Bitwarden released CLI 2026.4.1 on April 23, 2026. The Bitwarden client release page later listed CLI 2026.4.2, released May 20, 2026. Do not treat either historical version as permanently “latest”; check the current official release page and verify the recommended version and checksums when you rebuild.
Installing a newer release removes the malicious package from the active installation, but it does not revoke credentials that an earlier process may have read. Credential rotation and investigation remain necessary for any environment that ran 2026.4.0 during the exposure period.
How can you check whether the affected CLI was installed?
Local commands provide useful leads but are not definitive forensic evidence. A later upgrade can erase the previous version from the current package listing, a lockfile can show intended rather than executed dependencies, and a CI runner may have been destroyed after the job completed.
Check a global installation
npm list -g @bitwarden/cli --depth=0
This command may show the currently installed global version. A result showing a clean version does not prove that 2026.4.0 was never installed or executed.
Check a project-local installation
npm list @bitwarden/cli
Run the command from the relevant project directory. Also check projects and workflows that install the CLI temporarily rather than declaring it as a long-term dependency.
Search manifests and lockfiles
grep -R '"@bitwarden/cli"' package.json package-lock.json npm-shrinkwrap.json yarn.lock pnpm-lock.yaml 2>/dev/null
Search results can show that a project requested the package, but they do not prove that the malicious release was downloaded during the 93-minute window. Review historical commits, CI job definitions, build logs, and image manifests as well.
Look for stronger historical evidence
- CI logs showing npm commands, resolved versions, installation times, and environment names.
- npm cache metadata and package contents on persistent developer machines or runners.
- Container image layers and artifact-repository records.
- Endpoint telemetry showing npm, Node.js, shell, file, and network activity during the affected period.
- Registry audit records showing package downloads, publishes, token use, or unexpected package metadata changes.
- Cloud and source-control audit logs covering the affected time window and the following period.
A global package may have been installed outside the current user’s home directory, and a temporary CI command may not appear in any project manifest. Search every machine, container, build runner, and developer environment that could have used the CLI.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsWhich credentials should affected organizations rotate?
Rotate credentials from a known-clean machine or environment. Do not limit recovery to the Bitwarden account password: the reported payload targeted secrets available to the process, including unrelated cloud, source-control, npm, and CI credentials.
Rank #4
- Standard 125Khz ID RFID keyfob, support 125khz proximity ID cards token tag duplication. Frequency : 125kHz; Sensing Distance: 2.5 to 10 cm (1 to 4 inch); Data Storage Life: 10 Years
- Note: These are blank key tags without pre-programmed card numbers. You cannot directly add them to RFID locks or use a card reader to read them. Before using, please write data(card numbers) into them by a 125kHz RFID card writer first.
- Product Size: 40*30*4mm(1.57*1.18*0.16 inch). High-Quality Copper Coil inside. Casing Material: ABS Plastic. Waterproof and heat-resistant.
- Chip: ATMEL T5577 (compatible with other universal 125kHz tags). Frequency: 125kHz; It's rewritable, and it can write in 125khz id format and H-ID WG 125khz format, can be customised to 26-bit Prox format. Compatible with T5567 T5577 EM4305.
- Applications: Hotel key chain, Access control systems, time attendance system, ticketing, packing card. This T5577 proximity key card can copy duplicate em4100 TK4100 ID Card Keychains tags.
| Environment or credential | Recovery action | Evidence to review |
|---|---|---|
| Bitwarden API keys and session-related credentials | Revoke and issue replacements according to the organization’s Bitwarden administration procedure. | API use, session activity, machine identities, and access from affected hosts. |
| npm access and automation tokens | Revoke tokens accessible to the package process; issue least-privilege replacements. | Publish history, package versions, maintainer changes, token use, and unexpected release metadata. |
| GitHub personal access tokens, deploy keys, Actions secrets, and app credentials | Revoke or rotate exposed tokens and keys; review repository and organization permissions. | Commits, tags, releases, workflow edits, secret access, new keys, and unusual login or API activity. |
| AWS access keys, role credentials, and sessions | Disable and replace long-lived keys; invalidate or shorten active sessions where applicable. | CloudTrail activity, source IPs, user agents, geographies, role assumptions, new users, and new keys. |
| Azure service-principal credentials | Rotate client secrets or certificates and review service-principal permissions. | Sign-in records, token use, role changes, and newly created credentials. |
| Google Cloud service-account keys and application-default credentials | Revoke exposed keys and issue replacements with narrower roles. | Cloud audit logs, service-account activity, API calls, and IAM changes. |
| SSH keys and deployment credentials | Replace keys accessible to the affected process and remove old authorized keys. | SSH authentication logs, source addresses, repository access, and deployment activity. |
| CI/CD, databases, registries, signing keys, and deployment secrets | Rotate every secret readable by the affected job or runner, including secrets not obviously related to Bitwarden. | Runner logs, environment-variable use, artifact changes, signing events, and deployment records. |
Observed absence of suspicious activity lowers confidence in successful misuse but does not prove that a readable credential was never copied. Treat secrets as exposed when the compromised process could read them and the cost of replacement is acceptable.
How should organizations investigate possible propagation?
Organizations should investigate both the original installation and what the package may have changed afterward. Review npm publishing history for unexpected versions, package metadata, and releases made by accounts that were accessible from the affected environment.
- Inspect GitHub commits, tags, releases, workflow files, repository permissions, deploy keys, and Actions configuration.
- Review cloud audit logs for unusual IP addresses, geographies, user agents, token use, role assumption, new access keys, and IAM changes.
- Check npm registry activity, package metadata, package ownership, and publish events.
- Review CI runner logs and evidence of environment-variable access.
- Compare
package.json, lockfiles, lifecycle scripts, and release artifacts with known-good revisions. - Look for new files, processes, persistence mechanisms, outbound connections, and unusual DNS requests on developer systems.
- Check whether the affected identity could publish or modify other packages, images, releases, or signed artifacts.
Teams should use the Unit 42 report for indicators of compromise and payload behavior, while checking the original report for updates before treating any indicator as complete or final.
Should you stop using the Bitwarden CLI?
Ordinary Bitwarden users do not need to uninstall the browser extension or desktop and mobile applications solely because the npm CLI release was compromised. A developer or organization that ran the affected npm package should pause CLI-based automation until the host, credentials, and installation path have been reviewed.
The npm installation route is convenient and fits Node.js workflows, but it adds trust dependencies involving npm publication, package metadata, lifecycle scripts, dependency resolution, and the release credentials used to publish the package. A native executable can avoid npm lifecycle scripts and the Node package-distribution path. Bitwarden documents native CLI downloads and SHA-256 checksum files in its CLI documentation.
| Installation route | Advantages | Trade-offs |
|---|---|---|
| npm package | Familiar to Node.js users; easy global installation; convenient for JavaScript and CI workflows. | Depends on npm publication, package metadata, lifecycle behavior, dependency resolution, and release-pipeline credentials. |
| Native CLI executable | Avoids npm lifecycle scripts and the npm package-distribution route; checksum files are documented by Bitwarden. | Requires platform-specific downloads, secure verification, and possible automation changes. A checksum obtained through the same compromised channel is not independent verification. |
Native binaries are not automatically risk-free. Users still need to trust Bitwarden’s release infrastructure and verify the download securely. The safer choice depends on the organization’s ability to pin versions, verify artifacts, isolate runners, restrict credentials, and monitor execution.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What does this incident mean for Bitwarden vault security?
This incident was a distribution and execution-path failure, not evidence that Bitwarden’s encrypted vault database was breached. A malicious CLI process can still be dangerous because a local process may access unlocked vault contents, session material, API credentials, environment variables, files, or other secrets supplied to its execution environment.
Recommended Free Tools
Vault encryption therefore does not eliminate the consequences of running untrusted software on a machine that can access secrets. At the same time, the presence of a malicious npm CLI release does not justify claiming that all Bitwarden vaults or all Bitwarden applications were hacked. The technically accurate description is that Bitwarden’s npm-distributed CLI package was compromised for a limited period.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What controls reduce the risk of a similar supply-chain incident?
No single password manager, scanner, or cloud-security product guarantees protection against a trusted package becoming malicious. Organizations need layered controls covering prevention, detection, and recovery.
- Pin package versions and review lockfile changes rather than allowing uncontrolled installs in privileged jobs.
- Use isolated, short-lived CI runners with narrowly scoped credentials.
- Keep cloud, source-control, npm, registry, and signing permissions separate where possible.
- Use secret-management systems to reduce hard-coded credentials, while remembering that an authorized compromised process can still read secrets it is allowed to access.
- Monitor package behavior, dependency changes, lifecycle scripts, registry publishing, and artifact integrity.
- Enable repository secret scanning, dependency review, code scanning, and audit logging where those controls fit the environment.
- Practice credential revocation and runner-rebuild procedures before an incident occurs.
For organizations evaluating tooling, Socket, Snyk, and JFrog Xray address different aspects of package and artifact risk. Bitwarden Secrets Manager is more directly relevant to machine credentials and CI/CD secrets, while GitHub Advanced Security focuses on repository-level controls. Cloud and post-compromise monitoring products such as Wiz and Palo Alto Networks Prisma Cloud address broader cloud and workload concerns. These products solve different problems and should not be presented as guaranteed defenses against this specific event.
Timeline and verified facts
| Item | Verified detail |
|---|---|
| Affected package | @bitwarden/cli |
| Affected version | 2026.4.0 |
| Distribution channel | npm |
| Exposure window | April 22, 2026, 5:57 p.m.–7:30 p.m. ET |
| Approximate duration | 93 minutes |
| Bitwarden’s assessment | No evidence of end-user vault-data access or production compromise |
| Immediate replacement | CLI 2026.4.1, released April 23, 2026 |
| Later listed release | CLI 2026.4.2, released May 20, 2026 |
| CVE | CVE-2026-42994 |
| Severity records | NVD CVSS 3.1: 9.8 Critical; MITRE CVSS 4.0: 8.8 High |
| Campaign connection | Broader Checkmarx supply-chain incident, according to Bitwarden |
| Researcher attribution | TeamPCP or @pcpcats, as reported by Palo Alto Networks and Unit 42 |
Read the Bitwarden statement, the NVD record, the official release history, and the technical research before making incident-response decisions. Release status and indicators can change, so organizations should use the current official sources rather than relying only on a historical article.
Frequently Asked Questions
Do I need to change my Bitwarden master password because of the npm CLI attack?
You do not need to change your Bitwarden master password solely because of this incident if you never installed or ran the affected npm CLI release. If the CLI ran on a machine where the master password, unlocked vault contents, session material, or related credentials were exposed, investigate that environment and follow Bitwarden’s current account-recovery guidance.
Was the Bitwarden vault database hacked?
Bitwarden said its investigation found no evidence that end-user vault data, production data, or production systems were accessed or compromised. The confirmed issue involved a malicious release of the npm-distributed CLI package, not a reported breach of the stored vault database.
Is Bitwarden CLI version 2026.4.1 safe to use?
Bitwarden released CLI 2026.4.1 on April 23, 2026, as the immediate replacement for the malicious 2026.4.0 release, and the release page later listed 2026.4.2. Check Bitwarden’s current official release page before installing, because a historical replacement should not be assumed to be the latest version.
What if I installed the affected package but found no suspicious activity?
A lack of suspicious activity does not prove that credentials were not copied. Preserve available logs, determine what the process could read, rotate credentials from a known-clean environment when practical, and review npm, GitHub, CI, endpoint, and cloud audit records.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Does uninstalling @bitwarden/cli remove the risk?
Uninstalling the package removes the active installation but does not revoke credentials that the malicious process may already have read. Affected environments also require cache and artifact cleanup, investigation, credential rotation, and often rebuilding the runner or workstation.
The Bottom Line
Bottom line: this was not a blanket compromise of Bitwarden or its vault database. The urgent response applies to systems that installed and ran @bitwarden/cli@2026.4.0 from npm between 5:57 p.m. and 7:30 p.m. ET on April 22, 2026. Treat those systems as potentially compromised: preserve evidence, stop affected jobs, remove the package, rotate every accessible credential, and investigate publishing, source-control, and cloud activity.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

