🦞Stalecollected in 15h

npm Package Hijack Installs OpenClaw on 90K Machines

PostLinkedIn
🦞Read original on OpenClaw.report

💡Supply-chain attack via npm hit 90K devs, secretly installing OpenClaw—check your setup now.

⚡ 30-Second TL;DR

What Changed

Hijacked publish token for Cline CLI npm package

Why It Matters

Major supply-chain attack on dev tools risks widespread OpenClaw deployment without consent. Developers must audit CLI tools amid rising npm threats.

What To Do Next

Run `npm audit` and scan for unauthorized OpenClaw installs on your dev machines.

Who should care:Developers & AI Engineers

Key Points

  • Hijacked publish token for Cline CLI npm package
  • Silently installs OpenClaw on developer machines
  • Affected ~90,000 weekly users over 8 hours

🧠 Deep Insight

Background and context from public sources — not the original article. 10 sources cited.

🔑 Enhanced Key Takeaways

  • The malicious version cline@2.3.0 was downloaded approximately 4,000 times before deprecation, far below the package's typical 90,000 weekly downloads[2][8].
  • The attack exploited a prior prompt injection vulnerability in Cline disclosed by researcher Adnan Khan, whose PoC on a test repository was discovered and weaponized by the attacker[2][10].
  • OpenClaw integrates deeply with messaging apps like WhatsApp, Telegram, Slack, Discord, iMessage, and Teams, amplifying risks from its broad system access[1][3].
  • Cline maintainers responded by revoking the token, deprecating 2.3.0, releasing fixed versions 2.4.0+, and switching to OIDC provenance via GitHub Actions[2][4].

🔮 Future ImplicationsAI analysis grounded in cited sources

Security vendors will classify OpenClaw as PUA or malware
Experts like David Shipley state EDR/MDR tools must block it to counter such supply chain bypasses that evade traditional detection[1].
npm packages will mandate OIDC over long-lived tokens
This incident highlights risks of compromised tokens like clinebotorg, prompting recommendations for provenance-based publishing[4].
AI agents face heightened scrutiny for prompt injection
The attack chained a known Cline prompt injection vuln, underscoring persistent risks in agentic apps with autonomous actions[2][3].

Timeline

2026-02
Adnan Khan discloses prompt injection vulnerability in Cline via PoC on test repo
2026-02-12
CVE-2026-25253 published detailing malicious link exploits for OpenClaw token theft
2026-02-17
Compromised npm token publishes malicious cline@2.3.0 installing OpenClaw; live for 8 hours with ~4K downloads
2026-02-20
Incident reported publicly; maintainers revoke token, deprecate version, and release fixes
📰

Weekly AI Recap

Read this week's curated digest of top AI events →

👉Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: OpenClaw.report

This is a summary, not the original. Read the source, or get the weekly briefing.

Weekly AI briefing

One email a week. Unsubscribe anytime.