Supply Chain Attack Secretly Installs OpenClaw for Cline Users
ID: 4c6b3220-98fc-50db-8779-e01329054dcd
STIX ID: report--4c6b3220-98fc-50db-8779-e01329054dcd
Feed Name: Dark Reading
A prompt-injection vulnerability in Cline's workflow was disclosed and subsequently abused to steal a publish token, enabling an attacker to push a poisoned npm package (Cline v2.3.0) that silently installed OpenClaw on users' systems; roughly 4,000 installs occurred over an eight-hour window before the compromised package was removed and Cline published v2.4.0. OpenClaw itself is not labeled traditional malware but runs a persistent Gateway daemon with broad system access, posing high risk for credential theft and persistent footholds—users are advised to update and scan for unauthorized installations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
