Rogue Agent Watch › Records › clinejection-cline-triage-npm-publish

Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm release

Disclosed · added to the index · last updated

Grades

Verification status
Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Significant — AI materially enabled or accelerated the operation, but was one of several important components.
Severity
High — Significant confirmed harm to one or more organizations.

Summary

Security researcher Adnan Khan found in late December 2025 that the Cline project's GitHub issue-triage workflow, which ran the Anthropic claude-code-action with shell access on issues filed by any user, could be steered by a crafted issue into exposing publication credentials. Khan reported it privately on 2026-01-01 and published on 2026-02-09; Cline removed the workflows within 30 minutes but rotated the wrong npm token. Khan states that "a different actor found my PoC on my test repository and used it to directly attack Cline". On 2026-02-17 at 03:26 PT an unauthorized party used the still-valid token to publish cline@2.3.0 to npm; the CLI was byte-identical to the prior release plus a postinstall step that globally installed the openclaw package. A corrected version shipped about eight hours later. Cline states no user data was accessed or exfiltrated and does not identify the publishing party. Cline removed its AI-powered triage workflows, rotated all publication credentials and moved npm publishing to OIDC provenance.

Impact as stated

Unauthorized cline@2.3.0 published to npm and available for about eight hours; the package added a postinstall step that globally installed another package. Cline states no user data was accessed or exfiltrated.

Facts as stated by sources

Actor
Unknown (an "unauthorized party" per Cline; the researcher states a different actor reused his proof-of-concept) (Unknown)
Category
Agent hijack / prompt injection
Models named
claude-opus-4-5-20251101
Model families
Claude (Anthropic)
Agentic autonomy level
Not applicable
Guardrail bypass
Indirect prompt injection
Attack lifecycle phases
Initial access, Credential access, Impact
Target sectors
Technology
Target countries
not stated
Organisations affected
1
Records exfiltrated
not stated

Framework mappings

None recorded upstream.

Mitigations as stated

  • Cline removed its AI-powered triage workflows; future automation is limited to read-only operations with no shell access.
  • Cline rotated all publication credentials, removed GitHub Actions cache use from workflows handling publication credentials, moved npm publishing to OIDC provenance with no long-lived tokens, and now verifies rotation against the credential itself.
  • Cline is establishing a formal vulnerability disclosure process with SLAs and third-party CI/CD audits.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Related records

Sources (2)

  1. Post-mortem: Unauthorized Cline CLI npm publish on February 17, 2026
    Cline · First-party disclosure · · no archive recorded
  2. Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager
    Adnan Khan · Blog · · no archive recorded

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "clinejection-cline-triage-npm-publish". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/clinejection-cline-triage-npm-publish.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction