logo

Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems

ID: 7302a790-a818-563e-bff6-4670fb03c0af

STIX ID: report--7302a790-a818-563e-bff6-4670fb03c0af

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-02-20

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

In a supply-chain compromise on Feb 17, 2026, an attacker used a compromised npm publish token to release Cline CLI v2.3.0 containing a postinstall script that silently installed the OpenClaw autonomous AI agent on developer machines. The breach is linked to "Clinejection," a chain of prompt injection against an automated GitHub issue-triage AI agent combined with GitHub Actions cache poisoning to steal publication credentials; the compromised package was downloaded roughly 4,000 times during an eight-hour window before the token was revoked and maintainers released v2.4.0.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.