
Research
/Security News
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
library-nodejs-test-util
Advanced tools
This is a common nodejs library for logging in aws lambda. It's a simple wrapper around console.log and decorates emitted log messages with some additional structure that is used by graylog to enhance our logging.
Add to your node project:
npm install --save @adastradev/astra-loggerYou can use the logger anywhere in your code base, but it's a singleton and
should be configured in each of your handlers, in order to tack on the
extra structure to each message. Specifically, you should ensure you
set the tenant_id:
Note Depending on your typescript config and linting rules, you may need to disable the import-name rule. Typescript has different rules for default imports.
handler script
// tslint:disable-next-line: import-name
import Log from '@adastradev/astra-logger';
Log.config({ tenant_id: <some id>});
Log.debug('here I am!');
Other scripts, like controllers
// tslint:disable-next-line: import-name
import Log from '@adastradev/astra-logger';
Log.info('Processing request with payload', someObject);
It's a standard typescript node project:
npm installVSCode is the editor of choice currently.
Tests are ran via mocha and use chai for assertions.
npm testFAQs
Test Utilities for nodejs services
We found that library-nodejs-test-util demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.

Research
/Security News
Docker and Socket have uncovered malicious Checkmarx KICS images and suspicious code extension releases in a broader supply chain compromise.

Product
Stay on top of alert changes with filtered subscriptions, batched summaries, and notification routing built for triage.