Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up

Incident 1680: Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Responded
Description: An unknown actor reportedly exploited prompt injection in Cline's Claude-powered GitHub issue-triage workflow and a GitHub Actions cache-poisoning path to obtain publication credentials. On February 17, 2026, a still-valid npm token was used to publish unauthorized cline@2.3.0, which installed OpenClaw without user intent. Cline said OpenClaw was non-malicious; it deprecated the release and revoked the token that day, while reporting that it found no evidence of user-data exposure.

Tools

New ReportNew ResponseDiscoverView History

Entities

View all entities
Alleged: Anthropic and AI agent system developers developed an AI system deployed by Cline Bot Inc. , AI agent system deployers and Threat actors, which harmed Cline Bot Inc. , Cline CLI users and Software developers.
Alleged implicated AI systems: Claude Code , AI agent systems , GitHub Actions , Cline CLI , npm registry , Claude Code Action and Claude

Incident Stats

Incident ID
1680
Report Count
5
Incident Date
2026-02-17
Editors
Daniel Atherton

Incident Reports

Reports Timeline

Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager+2
Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw - Response
Cline CLI npm Package Compromised via Suspected Cache Poisoning AttackPost-mortem: Unauthorized Cline CLI npm publish on February 17, 2026 - Response
Loading...
Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager

Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager

adnanthekhan.com

Loading...
Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw

Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw

github.com

Loading...
Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw

Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw

stepsecurity.io

Loading...
Cline CLI npm Package Compromised via Suspected Cache Poisoning Attack

Cline CLI npm Package Compromised via Suspected Cache Poisoning Attack

socket.dev

Loading...
Post-mortem: Unauthorized Cline CLI npm publish on February 17, 2026

Post-mortem: Unauthorized Cline CLI npm publish on February 17, 2026

cline.bot

Loading...
Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager
adnanthekhan.com · 2026

UPDATE - NPM Package

To make sure it's clear in the midst of the NPM package situation: I did NOT conduct overt testing on Cline's repository.

I conducted my PoC on a mirror of Cline to confirm the prompt injection vulnerability. A differen…

Loading...
Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw
github.com · 2026
John Simone post-incident response

Package

 cline (npm)

Affected versions

2.3.0

Patched versions

=2.4.0

Description

Description

On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM regis…

Loading...
Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw
stepsecurity.io · 2026

Overview

On February 17, 2026 at 11:40 UTC, the StepSecurity npm monitoring system detected a suspicious release of the cline npm package. Version 2.3.0 of this widely-used autonomous coding agent CLI was published with a malicious post-ins…

Loading...
Cline CLI npm Package Compromised via Suspected Cache Poisoning Attack
socket.dev · 2026

On February 17, 2026, an unauthorized party used a compromised npm publish token to push cline@2.3.0 to the npm registry. Cline is a popular AI coding agent CLI in the developer ecosystem, with around 90,000 weekly downloads from npm. The m…

Loading...
Post-mortem: Unauthorized Cline CLI npm publish on February 17, 2026
cline.bot · 2026
Cline, Saoud Rizwan post-incident response

At 3:26 AM PT on February 17th, an unauthorized party used a compromised npm publish token to publish cline@2.3.0 to npm. The published package contained a single modification: an added postinstall script (npm install -g openclaw@latest) th…

Variants

A "variant" is an AI incident similar to a known case—it has the same causes, harms, and AI system. Instead of listing it separately, we group it under the first reported incident. Unlike other incidents, variants do not need to have been reported outside the AIID. Learn more from the research paper.
Seen something similar?

Similar Incidents

By textual similarity

Did our AI mess up? Flag the unrelated incidents

Loading...
GitHub Copilot, Copyright Infringement and Open Source Licensing

GitHub Copilot, Copyright Infringement and Open Source Licensing

Jun 2021 · 5 reports
Loading...
DALL-E Mini Reportedly Reinforced or Exacerbated Societal Biases in Its Outputs as Gender and Racial Stereotypes

DALL-E Mini Reportedly Reinforced or Exacerbated Societal Biases in Its Outputs as Gender and Racial Stereotypes

Jun 2022 · 4 reports
Loading...
YouTube’s Recommendation Algorithm Allegedly Promoted Climate Misinformation Content

YouTube’s Recommendation Algorithm Allegedly Promoted Climate Misinformation Content

Feb 2019 · 2 reports
Previous IncidentNext Incident

Similar Incidents

By textual similarity

Did our AI mess up? Flag the unrelated incidents

Loading...
GitHub Copilot, Copyright Infringement and Open Source Licensing

GitHub Copilot, Copyright Infringement and Open Source Licensing

Jun 2021 · 5 reports
Loading...
DALL-E Mini Reportedly Reinforced or Exacerbated Societal Biases in Its Outputs as Gender and Racial Stereotypes

DALL-E Mini Reportedly Reinforced or Exacerbated Societal Biases in Its Outputs as Gender and Racial Stereotypes

Jun 2022 · 4 reports
Loading...
YouTube’s Recommendation Algorithm Allegedly Promoted Climate Misinformation Content

YouTube’s Recommendation Algorithm Allegedly Promoted Climate Misinformation Content

Feb 2019 · 2 reports

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • dd3f754