Sev0AI security incidents, tracked

All incidents / Manipulated AI

Prompt injection in Cline's Claude triage bot led to a rogue npm release

Cline, disclosed Feb 2026. Manipulated AI Data exposed High

Cline's AI issue triage bot accepted input from any GitHub user and could run shell commands, so a crafted issue could make it leak an npm publish token. After an incomplete fix, an attacker used the token to publish a rogue Cline release that silently installed OpenClaw on about 4,000 machines.

Disclosed
Feb 2026
Organization
Cline
Vendor
Anthropic
Product
Cline (open source)
Type of AI
Coding assistant
How it happened
Manipulated AI: Prompt injection
Harm
Data exposed
Data involved
Credentials
Reach
Many organizations
Records
4,000
Severity
High
Model at fault
Yes
Status
Confirmed
Vulnerability IDs
GHSA-9ppg-jx86-fqw7

Sources

  1. https://cline.bot/blog/post-mortem-unauthorized-cline-cli-npm
  2. https://github.com/advisories/GHSA-9ppg-jx86-fqw7

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Prompt injection in Cline's Claude triage bot led to a rogue npm release", https://sev0.fyi/incidents/2026-02-01-cline-clinejection-npm-token/