AI incident ·
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package
In brief
An AI system built by Anthropic and AI agent system developers and deployed by Threat actors, Cline Bot Inc. and 1 other allegedly harmed Software developers, Cline CLI users and 1 other.
- Risk domain
- Not classified
- Occurred
- Coverage
- 5 reports
What happened
An unknown actor reportedly exploited prompt injection in Cline's Claude-powered GitHub issue-triage workflow and a GitHub Actions cache-poisoning path to obtain publication credentials. On February 17, 2026, a still-valid npm token was used to publish unauthorized [email protected], which installed OpenClaw without user intent. Cline said OpenClaw was non-malicious; it deprecated the release and revoked the token that day, while reporting that it found no evidence of user-data exposure.
Laws that address this harm
No recorded instrument yet addresses this use case where it happened. See the open queue.
Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).
News reports (5)
Titles link to the original publisher; report text is not reproduced here.
Who was involved
- Alleged deployer
- Threat actors Cline Bot Inc. AI agent system deployers
- Alleged developer
- Anthropic AI agent system developers
- Alleged harmed party
- Software developers Cline CLI users Cline Bot Inc.
AI systems implicated
npm registryGitHub ActionsCline CLIClaude Code ActionClaude CodeClaudeAI agent systems
Classification (MIT AI Risk Repository taxonomy)
- Risk domain
- —
- Risk subdomain
- —
- Causal entity
- —
- Intent
- —
- Timing
- —
- Harm level
- —
- Sectors
- —
- Countries
- —
Related incidents
Linked by editors or by text similarity in the source dataset.
Other incidents involving Threat actors
- AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Anthropic-Designated GTG-87001 Weapons Cell in Northern Yemen Reportedly Used Claude Code to Develop Missile Guidance Software
- Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns
- Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
- Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook
Source record: incident #1680 on the AI Incident Database · all 5 reports