AI incident #1680 ·

Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Open on the AI Incident Database 5 news reports Synced from the AIID API · record last edited 8 Sep 2026

What happened

An unknown actor reportedly exploited prompt injection in Cline's Claude-powered GitHub issue-triage workflow and a GitHub Actions cache-poisoning path to obtain publication credentials. On February 17, 2026, a still-valid npm token was used to publish unauthorized cline@2.3.0, which installed OpenClaw without user intent. Cline said OpenClaw was non-malicious; it deprecated the release and revoked the token that day, while reporting that it found no evidence of user-data exposure.

Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.

News reports (5)

Coverage catalogued by the AI Incident Database. Titles link to the original publisher; the text is not reproduced here.

Who was involved

Alleged harmed party
Software developers Cline CLI users Cline Bot Inc.
On AIID: Software developers, Cline CLI users, Cline Bot Inc.

AI systems implicated

npm registryGitHub ActionsCline CLIClaude Code ActionClaude CodeClaudeAI agent systems

Classification (MIT AI Risk Repository taxonomy)

Risk domain
Risk subdomain
Causal entity
Intent
Timing
Harm level
Sectors
Countries

Linked by AIID editors or by its text-similarity model.

Other incidents involving Threat actors