Skip to Content
logologo
AI Incident Database
Donar
Descubrir
Enviar
  • Bienvenido a la AIID
  • Vista Tabular
  • Vista de lista
  • Entidades
  • Taxonomías
  • Vista espacial
  • Blog
  • Resumen de noticias de IA
  • Incidente aleatorio
  • Registrarse
Descubrir
Enviar
  • Bienvenido a la AIID
  • Vista Tabular
  • Vista de lista
  • Entidades
  • Taxonomías
  • Vista espacial
  • Blog
  • Resumen de noticias de IA
  • Incidente aleatorio
  • Registrarse
Entidades

npm registry

Incidents implicated systems

Incidente 16805 Reportes
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

2026-02-17

An unknown actor reportedly exploited prompt injection in Cline's Claude-powered GitHub issue-triage workflow and a GitHub Actions cache-poisoning path to obtain publication credentials. On February 17, 2026, a still-valid npm token was used to publish unauthorized cline@2.3.0, which installed OpenClaw without user intent. Cline said OpenClaw was non-malicious; it deprecated the release and revoked the token that day, while reporting that it found no evidence of user-data exposure.

Más

Incidente 12102 Reportes
Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

2025-08-21

Malicious versions of the popular Nx monorepo tool and plugins were reportedly published to npm after attackers compromised its CI workflow. The malware's postinstall script reportedly harvested credentials and exfiltrated data, reportedly weaponizing local AI coding agents such as Claude Code, Gemini, and Amazon q. By invoking unsafe flags, it allegedly coerced the tools into scanning developer machines for sensitive files, marking one of the first known AI-assisted supply chain attacks.

Más

Entidades relacionadas
Otras entidades que están relacionadas con el mismo incidente. Por ejemplo, si el desarrollador de un incidente es esta entidad pero el implementador es otra entidad, se marcan como entidades relacionadas.
 

Entity

Malicious actors compromising Nx’s CI/CD pipeline and publishing tainted npm packages

Incidents involved as Deployer
  • Incidente 1210
    2 Report

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

Más
Entity

Anthropic

Incidents involved as Developer
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

  • Incidente 1210
    2 Report

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

Más
Entity

Google

Incidents involved as Developer
  • Incidente 1210
    2 Report

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

Más
Entity

Amazon

Incidents involved as Developer
  • Incidente 1210
    2 Report

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

Más
Entity

Nx users and organizations installing compromised npm packages

Afectado por Incidentes
  • Incidente 1210
    2 Report

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

Más
Entity

Nx (monorepo tool and plugins)

Incidents implicated systems
  • Incidente 1210
    2 Report

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

Más
Entity

Claude Code CLI

Incidents implicated systems
  • Incidente 1210
    2 Report

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

Más
Entity

Google Gemini CLI

Incidents implicated systems
  • Incidente 1210
    2 Report

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

Más
Entity

Amazon q CLI

Incidents implicated systems
  • Incidente 1210
    2 Report

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

Más
Entity

GitHub

Incidents implicated systems
  • Incidente 1210
    2 Report

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration

Más
Entity

Cline Bot Inc.

Afectado por Incidentes
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Incidents involved as Deployer
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Más
Entity

AI agent system deployers

Incidents involved as Deployer
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Más
Entity

Threat actors

Incidents involved as Deployer
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Más
Entity

AI agent system developers

Incidents involved as Developer
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Más
Entity

Cline CLI users

Afectado por Incidentes
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Más
Entity

Software developers

Afectado por Incidentes
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Más
Entity

Claude Code

Incidents implicated systems
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Más
Entity

AI agent systems

Incidents implicated systems
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Más
Entity

GitHub Actions

Incidents implicated systems
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Más
Entity

Cline CLI

Incidents implicated systems
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Más
Entity

Claude Code Action

Incidents implicated systems
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Más
Entity

Claude

Incidents implicated systems
  • Incidente 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Más

Investigación

  • Definición de un “Incidente de IA”
  • Definición de una “Respuesta a incidentes de IA”
  • Hoja de ruta de la base de datos
  • Trabajo relacionado
  • Descargar Base de Datos Completa

Proyecto y Comunidad

  • Acerca de
  • Contactar y Seguir
  • Aplicaciones y resúmenes
  • Guía del editor

Incidencias

  • Todos los incidentes en forma de lista
  • Incidentes marcados
  • Cola de envío
  • Vista de clasificaciones
  • Taxonomías

2026 - AI Incident Database

  • Condiciones de uso
  • Política de privacidad
  • dd3f754