{ "actor": "Unknown (an \"unauthorized party\" per Cline; the researcher states a different actor reused his proof-of-concept)", "actor_type": "unknown", "added": { "by": "MLSecOpsHub", "date": "2026-10-10" }, "ai_role": "significant", "autonomy_level": "not-applicable", "autonomy_pct": null, "category": "agent-hijack-prompt-injection", "confidence": "primary", "date_disclosed": "2026-02-09", "guardrail_bypass": [ "indirect-prompt-injection" ], "id": "clinejection-cline-triage-npm-publish", "impact": "Unauthorized cline@2.3.0 published to npm and available for about eight hours; the package added a postinstall step that globally installed another package. Cline states no user data was accessed or exfiltrated.", "last_updated": "2026-10-10", "lifecycle_phases": [ "initial-access", "credential-access", "impact" ], "mappings": { "aiid": [], "cve": [], "mitre_atlas": [], "mitre_attack": [], "owasp_asi": [], "owasp_llm": [] }, "mitigations": [ "Cline removed its AI-powered triage workflows; future automation is limited to read-only operations with no shell access.", "Cline rotated all publication credentials, removed GitHub Actions cache use from workflows handling publication credentials, moved npm publishing to OIDC provenance with no long-lived tokens, and now verifies rotation against the credential itself.", "Cline is establishing a formal vulnerability disclosure process with SLAs and third-party CI/CD audits." ], "model_families": [ "claude" ], "models": [ "claude-opus-4-5-20251101" ], "name": "Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm release", "related": [ "nx-s1ngularity-supply-chain", "camoleak-github-copilot-chat" ], "severity": "high", "sources": [ { "date": "2026-02-24", "publisher": "Cline", "title": "Post-mortem: Unauthorized Cline CLI npm publish on February 17, 2026", "type": "first-party-disclosure", "url": "https://cline.bot/blog/post-mortem-unauthorized-cline-cli-npm" }, { "date": "2026-02-09", "publisher": "Adnan Khan", "title": "Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager", "type": "blog", "url": "https://adnanthekhan.com/posts/clinejection/" } ], "status": "confirmed", "summary": "Security researcher Adnan Khan found in late December 2025 that the Cline project's GitHub issue-triage workflow, which ran the Anthropic claude-code-action with shell access on issues filed by any user, could be steered by a crafted issue into exposing publication credentials. Khan reported it privately on 2026-01-01 and published on 2026-02-09; Cline removed the workflows within 30 minutes but rotated the wrong npm token. Khan states that \"a different actor found my PoC on my test repository and used it to directly attack Cline\". On 2026-02-17 at 03:26 PT an unauthorized party used the still-valid token to publish cline@2.3.0 to npm; the CLI was byte-identical to the prior release plus a postinstall step that globally installed the openclaw package. A corrected version shipped about eight hours later. Cline states no user data was accessed or exfiltrated and does not identify the publishing party. Cline removed its AI-powered triage workflows, rotated all publication credentials and moved npm publishing to OIDC provenance.", "targets": { "countries": [], "orgs_affected": 1, "records_exfiltrated": null, "sectors": [ "technology" ] } }