BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

AI Tool Cline CLI Hijacked in Supply Chain Attack

Compromised Cline CLI npm package installs OpenClaw AI agent via stolen token.

  • The AI-powered Cline CLI npm package was compromised, leading to an unauthorized update that installed the OpenClaw AI agent on developer machines.
  • The breach, attributed to a stolen npm publish token, affected around 4,000 downloads over an eight-hour window on February 17, 2026.
  • Security researchers link the attack to a prior vulnerability called “Clinejection,” where prompt injection in GitHub issues could steal publishing credentials.
  • Maintainers have deprecated the malicious version, revoked the token, and updated their publishing security.

In a significant software supply chain attack, the open-source Cline CLI coding assistant was compromised on February 17, 2026, leading to an unauthorized update that secretly installed OpenClaw on developers’ systems. The attack, spotted by the Microsoft Threat Intelligence team, resulted from a stolen npm publish token used to release a malicious version, according to an advisory.

- Advertisement -

Consequently, the package’s `postinstall` script forced an automatic OpenClaw installation for anyone downloading version 2.3.0. StepSecurity data shows roughly 4,000 downloads occurred during the eight-hour compromise window before the package was deprecated.

Meanwhile, researchers traced the breach’s origins to a vulnerability dubbed “Clinejection,” discovered by Adnan Khan. This flaw allowed attackers to use prompt injection on GitHub issues to execute arbitrary commands and steal high-privilege publication tokens.

This method could poison a repository’s build cache and pivot to a release workflow, exactly what happened to obtain the npm token. The stolen credential was then used to authenticate and publish the compromised package to the registry.

However, Endor Labs researcher Henrik Plate assessed the overall impact as low, noting “OpenClaw itself is not malicious.” The incident did not affect Cline’s VS Code extension or JetBrains plugin.

- Advertisement -

Consequently, maintainers have revoked the token, deprecated version 2.3.0, and released a secure version 2.4.0. They also updated their npm publishing to use more secure OpenID Connect authentication via GitHub Actions.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ethereum Surges 58% in Q3, on Track to End Record Losing Streak

Ethereum has surged nearly 58% in the third quarter, on track to end a...

Anthropic CEO warns AI speed may outrun control

Anthropic CEO Dario Amodei warns that unchecked AI development may outrun human control, citing...

AMC CEO Questions If Robinhood Stock Tokens Are Truly 1:1 Backed

AMC CEO Adam Aron questioned whether Robinhood stock tokens remain fully 1:1 backed when...

GTA V mod adds 235 simulated Flock cameras to track players

Modder WTTDOTM has added 235 simulated Flock surveillance cameras to Grand Theft Auto V.The...

Tom Lee: Inflation Less Severe; Bullish on Ethereum

Tom Lee argues portfolio fees and flash memory prices distort inflation metrics, making the...

Must Read

What Are Anonymous Debit Cards And How Do They Work?

You've heard about anonymous debit cards, but what are they really? Anonymous Debit Cards are cards that let you make purchases without revealing your...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading