The attack leverages a trojanized npm package to steal credentials from developer environments connected to Bitwarden CLI workflows.