AIPolicyTracker

AI incident ·

Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

5 news reports Synced from source · record last edited 8 Sep 2026

In brief

An AI system built by Anthropic and AI agent system developers and deployed by Threat actors, Cline Bot Inc. and 1 other allegedly harmed Software developers, Cline CLI users and 1 other.

Risk domain
Not classified
Occurred
Coverage
5 reportsFeb 2026

What happened

An unknown actor reportedly exploited prompt injection in Cline's Claude-powered GitHub issue-triage workflow and a GitHub Actions cache-poisoning path to obtain publication credentials. On February 17, 2026, a still-valid npm token was used to publish unauthorized [email protected], which installed OpenClaw without user intent. Cline said OpenClaw was non-malicious; it deprecated the release and revoked the token that day, while reporting that it found no evidence of user-data exposure.

Laws that address this harm

No recorded instrument yet addresses this use case where it happened. See the open queue.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

News reports (5)

Titles link to the original publisher; report text is not reproduced here.

Who was involved

Alleged harmed party
Software developers Cline CLI users Cline Bot Inc.

AI systems implicated

npm registryGitHub ActionsCline CLIClaude Code ActionClaude CodeClaudeAI agent systems

Classification (MIT AI Risk Repository taxonomy)

Risk domain
—
Risk subdomain
—
Causal entity
—
Intent
—
Timing
—
Harm level
—
Sectors
—
Countries
—

Linked by editors or by text similarity in the source dataset.

Other incidents involving Threat actors

Source record: incident #1680 on the AI Incident Database · all 5 reports