<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #cicd</title><description>Articles tagged cicd on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>Bitwarden CLI got backdoored for 90 minutes. The worm calls itself &apos;Shai-Hulud: The Third Coming.&apos;</title><link>https://devtake.dev/article/bitwarden-cli-shai-hulud-npm-worm/</link><guid isPermaLink="true">https://devtake.dev/article/bitwarden-cli-shai-hulud-npm-worm/</guid><description>A malicious @bitwarden/cli@2026.4.0 hit npm on April 22. The payload steals npm tokens, cloud secrets, and Claude Code credentials, then self-replicates.</description><pubDate>Thu, 23 Apr 2026 19:00:00 GMT</pubDate><category>security</category><category>bitwarden</category><category>shai-hulud</category><category>npm</category><category>supply-chain</category><category>worm</category><category>credential-theft</category><category>checkmarx</category><category>cicd</category><author>luca-reinhardt</author></item><item><title>Trivy got hijacked: 75 of 76 version tags rewrote to drop a CI secret-stealer</title><link>https://devtake.dev/article/trivy-supply-chain-attack-compromise/</link><guid isPermaLink="true">https://devtake.dev/article/trivy-supply-chain-attack-compromise/</guid><description>Attackers force-pushed 75 of 76 trivy-action tags to a malicious commit. Pinning by tag turned a trusted scanner into an infostealer for CI pipelines.</description><pubDate>Sat, 18 Apr 2026 08:30:00 GMT</pubDate><category>security</category><category>supply-chain</category><category>trivy</category><category>aqua-security</category><category>github-actions</category><category>cicd</category><category>devsecops</category><category>teampcp</category><author>luca-reinhardt</author></item></channel></rss>