Cline CLI 2.3.0 was published with a stolen npm token, installing OpenClaw in an 8-hour attack affecting ~4,000 downloads.
Someone compromised open source AI coding assistant Cline CLI's npm package earlier this week in an odd supply chain attack ...
The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.
While the AI itself wasn’t weaponized, the technique raises concerns about AI agents with broad system access.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results