📰較早收集於 2m

駭客誘騙 Cline 散播 OpenClaw

駭客誘騙 Cline 散播 OpenClaw
PostLinkedIn
📰閱讀原文: The Verge
#prompt-injection#ai-agent#supply-chaincline

💡Cline vuln lets hackers spread rogue AI agents—audit your coding tools now!

⚡ 30-Second TL;DR

有什麼變化

駭客利用 Cline 的 Claude 整合進行提示注入

為什麼重要

依賴 AI 程式碼代理的開發者面臨透過提示操控的新供應鏈攻擊途徑。此事件可能侵蝕對 Cline 等工具的信任,促使代理工作流程實施更嚴格防護。

下一步行動

Scan Cline installations for OpenClaw and patch prompt injection vulns using Adnan Khan's PoC.

誰應關注:Developers & AI Engineers

關鍵要點

  • 駭客利用 Cline 的 Claude 整合進行提示注入
  • 在開發者系統中安裝 OpenClaw AI 代理
  • Adnan Khan 數日前揭露漏洞概念驗證
  • 凸顯自主 AI 在使用者機器上的危險

🧠 深度解析

背景與延伸:來自公開資料,非原文內容。引用 5 個來源。

🔑 增強重點摘要

  • A hacker exploited a prompt injection vulnerability in Cline's Claude Issue Triage GitHub Actions workflow, active from Dec 21, 2025 to Feb 9, 2026, to steal npm, VSCE, and OVSX publishing tokens via cache poisoning[1][3].
  • On February 17, 2026, the attacker published malicious Cline CLI version 2.3.0 to npm, which included a postinstall script silently installing the legitimate OpenClaw AI agent globally on users' systems[1][3][4].
  • The malicious version remained live for about 8 hours until Cline team published fixed version 2.4.0 and deprecated 2.3.0, with the advisory rating severity as 'low' since OpenClaw is open-source but highlighting supply chain risks[1][2][4].
  • Security researcher Adnane Khan discovered and reported the prompt injection flaw on January 1, 2026, providing a proof-of-concept using public tools like Cacheract for cache poisoning[3].
  • This incident underscores accelerating npm supply chain attacks on AI dev tools, with prior OpenClaw 'ClawHavoc' attack in January 2026 planting malicious skills for infostealers[1][2].

🛠️ 技術深入

  • Prompt injection targeted Cline's Claude Issue Triage workflow (removed post-incident), allowing GitHub account holders to inject malicious instructions chaining to GitHub Actions cache poisoning[3].
  • Cache poisoning used tools like Cacheract to flush/evict cache, pivot to Publish Nightly Release/NPM workflows, stealing VSCE_PAT, OVSX_PAT, NPM_RELEASE_TOKEN secrets with production-level access[3].
  • Malicious npm package 2.3.0 modified only package.json to add 'postinstall': 'npm install -g openclaw@latest' lifecycle script; CLI binary dist/cli.mjs unchanged from legit 2.2.0[1].
  • Attack drew from public research like Aikido Security’s PromptPwned on AI workflow misconfigurations[3].
  • Cline CLI 2.0 features AI agent control in terminal with parallel execution, headless CI/CD, ACP editor support[5].

🔮 前景展望AI analysis grounded in cited sources

This supply chain attack via AI prompt injection in CI/CD pipelines signals heightened risks for autonomous AI agents in dev tools, potentially enabling credential theft or malware distribution; accelerates scrutiny on npm/GitHub Actions security and trust in AI-assisted automation[1][2][3].

時間線

2025-12-21
Prompt injection vulnerability active in Cline's Claude Issue Triage workflow begins
2026-01-01
Adnane Khan reports Clinejection vulnerability with proof-of-concept
2026-01
ClawHavoc attack plants malicious skills on OpenClaw's ClawHub marketplace
2026-02-09
Cline removes vulnerable Claude Issue Triage workflow
2026-02-17
Attacker publishes malicious Cline CLI v2.3.0 with OpenClaw postinstall script; fixed v2.4.0 released same day
📰

AI 週報

閱讀本週精選 AI 大事摘要 →

👉相關動態

AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: The Verge

這是摘要,不是原文。去看原站,或訂閱每週簡報。

每週 AI 簡報

每週一封,可隨時退訂。