AI incident #1680 ·
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package
What happened
An unknown actor reportedly exploited prompt injection in Cline's Claude-powered GitHub issue-triage workflow and a GitHub Actions cache-poisoning path to obtain publication credentials. On February 17, 2026, a still-valid npm token was used to publish unauthorized cline@2.3.0, which installed OpenClaw without user intent. Cline said OpenClaw was non-malicious; it deprecated the release and revoked the token that day, while reporting that it found no evidence of user-data exposure.
Only the incident metadata is stored here. The underlying news reports are on the AI Incident Database (CC BY-SA 4.0); use the links above to read them.
News reports (5)
Coverage catalogued by the AI Incident Database. Titles link to the original publisher; the text is not reproduced here.
Who was involved
- Alleged deployer
- Threat actors Cline Bot Inc. AI agent system deployers
- Alleged developer
- Anthropic AI agent system developers
- Alleged harmed party
- Software developers Cline CLI users Cline Bot Inc.
AI systems implicated
npm registryGitHub ActionsCline CLIClaude Code ActionClaude CodeClaudeAI agent systems
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —
Related incidents on the AI Incident Database
Linked by AIID editors or by its text-similarity model.