A Prompt Injection Attack Hijacked a Developer Tool's npm Credentials and Pushed a Fake Release
What happened
On February 17, 2026, anyone who installed what appeared to be a routine update to a popular AI coding tool got something they did not ask for. The npm package cline@2.3.0, published that day, was not a legitimate release. It had been pushed by an unknown actor using credentials stolen through the tool's own automated workflow, and it silently installed a separate package called OpenClaw on every machine that picked it up.
The credentials came from two attack paths working in combination. Cline ran an AI-powered GitHub issue-triage workflow, a system that read incoming bug reports and took automated actions in response. An attacker found a way to inject malicious instructions into that workflow through the content of a GitHub issue, exploiting a prompt injection vulnerability. A second path, GitHub Actions cache poisoning, provided a route to the npm token that governed package publication. Together, the two paths gave the attacker everything needed to publish as if they were Cline itself.
The published package installed OpenClaw without the user's knowledge or consent. Cline subsequently assessed OpenClaw as non-malicious, and the company found no evidence that user data was exposed. But the intent of the attacker, or the full capability of what was installed, could not be confirmed with certainty at the time. Users who updated their tooling in the hours between publication and takedown had software on their machines they had not agreed to install.
Cline moved quickly once the issue was detected. The cline@2.3.0 release was deprecated the same day, the compromised npm token was revoked, and the company published an account of what it believed had happened. The response was faster than most supply-chain incidents of this kind, and the practical damage appears to have been contained. What the speed of response could not address is the structural question: an automated AI workflow with write access to a production package registry had inadequate guards against adversarial input arriving through a public issue tracker.
The gap this incident reveals is not primarily a coding flaw or a missing patch. It is the absence of a provable record of what a system did on behalf of a user, who authorized each action, and what inputs the automation processed before acting. A workflow that can publish to npm, triggered in part by untrusted external text, requires a verification layer that logs every step and flags when the triggering input came from outside the development team. Without that layer, the question of whether a human authorized a given release has no reliable answer, and the next attacker willing to study an open-source project's automated workflows will find the same surface waiting for them.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.