Entities
View all entitiesIncident Stats
Incident Reports
Reports Timeline
UPDATE - NPM Package
To make sure it's clear in the midst of the NPM package situation: I did NOT conduct overt testing on Cline's repository.
I conducted my PoC on a mirror of Cline to confirm the prompt injection vulnerability. A differen…
Package
cline (npm)
Affected versions
2.3.0
Patched versions
=2.4.0
Description
Description
On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM regis…
Overview
On February 17, 2026 at 11:40 UTC, the StepSecurity npm monitoring system detected a suspicious release of the cline npm package. Version 2.3.0 of this widely-used autonomous coding agent CLI was published with a malicious post-ins…
On February 17, 2026, an unauthorized party used a compromised npm publish token to push cline@2.3.0 to the npm registry. Cline is a popular AI coding agent CLI in the developer ecosystem, with around 90,000 weekly downloads from npm. The m…
At 3:26 AM PT on February 17th, an unauthorized party used a compromised npm publish token to publish cline@2.3.0 to npm. The published package contained a single modification: an added postinstall script (npm install -g openclaw@latest) th…


