Prompt injection in Cline's Claude triage bot led to a rogue npm release
What happened
Cline's AI issue triage bot accepted input from any GitHub user and could run shell commands, so a crafted issue could make it leak an npm publish token. After an incomplete fix, an attacker used the token to publish a rogue Cline release that silently installed OpenClaw on about 4,000 machines.
In December 2025 Cline, an open-source AI coding assistant, added a GitHub workflow in which Claude, through Anthropic's claude-code-action, triaged every new issue. It was configured so that anyone on GitHub could trigger it, the issue title was pasted straight into Claude's instructions, and the bot had broad tools that included running commands. Security researcher Adnan Khan showed that a crafted issue title could make it install code from an attacker's repository. From there the attacker's code flooded the workflow cache and planted poisoned entries, which the nightly release job later restored, leaking its npm, VS Code Marketplace and Open VSX publishing tokens. Khan reported the chain on 1 January 2026 and followed up for five weeks without a response before disclosing it publicly on 9 February.
Cline removed the triage workflow within 30 minutes of the disclosure and began rotating credentials, but revoked the wrong npm token. On 17 February an unknown party used the still-valid token to publish cline 2.3.0, identical to the previous release apart from one added line that silently installed the OpenClaw AI agent on every machine that installed or updated Cline during the next eight hours, about 4,000 downloads.
How it happened
Manipulated AI: Prompt injection. Hidden instructions planted in content the AI was reading, such as an email, web page or issue, made it act for the attacker.
The AI involved was from Anthropic. The product was Cline, which is open source, a type of coding assistant. Vulnerability IDs: GHSA-9ppg-jx86-fqw7.
Impact
Data was exposed. Data involved: credentials. Many organizations were affected. Sources give a figure of 4,000.
Severity is rated High, calculated from how far the incident reached and how sensitive the data was.
Was the AI at fault?
Yes. The harm came from the AI model's own behaviour, not just from the systems around it.
Status and timeline
Confirmed by the affected organization, the AI vendor, a regulator or a named security research firm.
It happened or began on 17 Feb 2026. It became public on 17 Feb 2026, 0 days later.
Cline published an advisory, pulled the rogue version after about eight hours and released a fixed version, saying the package contained no other malicious changes. Security firm Snyk named the attack chain Clinejection.