On April 22, version 2026.4.0 of @bitwarden/cli was live on npm for ninety-three minutes as a credential stealer (Bitwarden statement via The Hacker News, now tracked as CVE-2026-42994). The reporting led with the cloud credentials it stole. What it also stole is the part worth paying attention to.

MCP (Model Context Protocol) servers are the interface AI tools use to access external systems: files, APIs, databases, internal services. The package pulled the usual haul - SSH keys, GitHub tokens, AWS, GCP, and Azure credentials, plus shell history. That part is standard supply chain behavior.

The newer pattern is AI tool targeting. The payload explicitly searched for AI tool configuration: Claude, Kiro, Cursor, Codex CLI, Aider, and MCP server configs on disk (The Hacker News, Aikido Security). This is not the first sample to do that. SANDWORM_MODE in February 2026 and the s1ngularity / Nx attack in August 2025 both swept AI tool directories (Endor Labs sandworm analysis, Wiz s1ngularity writeup). What this incident adds is a high-profile package and a trusted-publishing delivery path that bypassed the usual long-lived-token controls. The trajectory is consistent: AI tool state is now a routine target, not an opportunistic one.

The delivery mechanism is also notable. Bitwarden's CI used checkmarx/ast-github-action, which got compromised first (Endor Labs). The malicious action then used Bitwarden's own npm trusted publishing flow, OpenID Connect from GitHub Actions to npm, to push the bad package without a long-lived API key ever existing. Researcher Adnan Khan called it one of the first publicly documented compromises of an npm trusted publishing pipeline (The Hacker News). Trusted publishing removed long-lived tokens from CI. The attack surface moved to the workflow itself.

The blast radius is not symmetric. Rotating a cloud credential is operationally understood. Rotating AI tool state is not. A leaked MCP server config exposes whatever that server connects to, which for most developers means the actual work: documents, databases, Notion vaults, Slack workspaces, calendars.

Local AI tooling is quietly becoming a high-value credential surface: broad access, long-lived tokens, and cross-system reach, all aggregated into a small number of files that are rarely treated as secrets.

If you ran npm install -g @bitwarden/cli in that ninety-three-minute window, treat the machine as compromised. Rotate the obvious things. Then rotate the AI things: Claude API keys, MCP server credentials, anything in ~/.claude, ~/.cursor, ~/.aider, ~/.codex. Look at GitHub for repos in your account with the description "Shai-Hulud: The Third Coming."

The ninety-three-minute window is what made the news. The AI config harvester is what will matter in twelve months.