Rogue Agent Watch › Records › clinejection-cline-triage-npm-publish
Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm release
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Significant — AI materially enabled or accelerated the operation, but was one of several important components.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
Security researcher Adnan Khan found in late December 2025 that the Cline project's GitHub issue-triage workflow, which ran the Anthropic claude-code-action with shell access on issues filed by any user, could be steered by a crafted issue into exposing publication credentials. Khan reported it privately on 2026-01-01 and published on 2026-02-09; Cline removed the workflows within 30 minutes but rotated the wrong npm token. Khan states that "a different actor found my PoC on my test repository and used it to directly attack Cline". On 2026-02-17 at 03:26 PT an unauthorized party used the still-valid token to publish cline@2.3.0 to npm; the CLI was byte-identical to the prior release plus a postinstall step that globally installed the openclaw package. A corrected version shipped about eight hours later. Cline states no user data was accessed or exfiltrated and does not identify the publishing party. Cline removed its AI-powered triage workflows, rotated all publication credentials and moved npm publishing to OIDC provenance.
Impact as stated
Unauthorized cline@2.3.0 published to npm and available for about eight hours; the package added a postinstall step that globally installed another package. Cline states no user data was accessed or exfiltrated.
Facts as stated by sources
- Actor
- Unknown (an "unauthorized party" per Cline; the researcher states a different actor reused his proof-of-concept) (Unknown)
- Category
- Agent hijack / prompt injection
- Models named
- claude-opus-4-5-20251101
- Model families
- Claude (Anthropic)
- Agentic autonomy level
- Not applicable
- Guardrail bypass
- Indirect prompt injection
- Attack lifecycle phases
- Initial access, Credential access, Impact
- Target sectors
- Technology
- Target countries
- not stated
- Organisations affected
- 1
- Records exfiltrated
- not stated
Framework mappings
None recorded upstream.
Mitigations as stated
- Cline removed its AI-powered triage workflows; future automation is limited to read-only operations with no shell access.
- Cline rotated all publication credentials, removed GitHub Actions cache use from workflows handling publication credentials, moved npm publishing to OIDC provenance with no long-lived tokens, and now verifies rotation against the credential itself.
- Cline is establishing a formal vulnerability disclosure process with SLAs and third-party CI/CD audits.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Related records
- Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools
- CamoLeak — GitHub Copilot Chat prompt-injection data exfiltration
Sources (2)
- Post-mortem: Unauthorized Cline CLI npm publish on February 17, 2026
Cline · First-party disclosure · · no archive recorded - Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager
Adnan Khan · Blog · · no archive recorded
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "clinejection-cline-triage-npm-publish". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/clinejection-cline-triage-npm-publish.json — CC BY-SA 4.0.