Prompt injection in Cline's Claude triage bot led to a rogue npm release
Cline's AI issue triage bot accepted input from any GitHub user and could run shell commands, so a crafted issue could make it leak an npm publish token. After an incomplete fix, an attacker used the token to publish a rogue Cline release that silently installed OpenClaw on about 4,000 machines.
- Disclosed
- Feb 2026
- Organization
- Cline
- Vendor
- Anthropic
- Product
- Cline (open source)
- Type of AI
- Coding assistant
- How it happened
- Manipulated AI: Prompt injection
- Harm
- Data exposed
- Data involved
- Credentials
- Reach
- Many organizations
- Records
- 4,000
- Severity
- High
- Model at fault
- Yes
- Status
- Confirmed
- Vulnerability IDs
- GHSA-9ppg-jx86-fqw7