Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems
ID: 7302a790-a818-563e-bff6-4670fb03c0af
STIX ID: report--7302a790-a818-563e-bff6-4670fb03c0af
Feed Name: The Hacker News
In a supply-chain compromise on Feb 17, 2026, an attacker used a compromised npm publish token to release Cline CLI v2.3.0 containing a postinstall script that silently installed the OpenClaw autonomous AI agent on developer machines. The breach is linked to "Clinejection," a chain of prompt injection against an automated GitHub issue-triage AI agent combined with GitHub Actions cache poisoning to steal publication credentials; the compromised package was downloaded roughly 4,000 times during an eight-hour window before the token was revoked and maintainers released v2.4.0.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
