駭客誘騙 Cline 散播 OpenClaw

💡Cline vuln lets hackers spread rogue AI agents—audit your coding tools now!
⚡ 30-Second TL;DR
有什麼變化
駭客利用 Cline 的 Claude 整合進行提示注入
為什麼重要
依賴 AI 程式碼代理的開發者面臨透過提示操控的新供應鏈攻擊途徑。此事件可能侵蝕對 Cline 等工具的信任,促使代理工作流程實施更嚴格防護。
下一步行動
Scan Cline installations for OpenClaw and patch prompt injection vulns using Adnan Khan's PoC.
關鍵要點
- •駭客利用 Cline 的 Claude 整合進行提示注入
- •在開發者系統中安裝 OpenClaw AI 代理
- •Adnan Khan 數日前揭露漏洞概念驗證
- •凸顯自主 AI 在使用者機器上的危險
🧠 深度解析
背景與延伸:來自公開資料,非原文內容。引用 5 個來源。
🔑 增強重點摘要
- •A hacker exploited a prompt injection vulnerability in Cline's Claude Issue Triage GitHub Actions workflow, active from Dec 21, 2025 to Feb 9, 2026, to steal npm, VSCE, and OVSX publishing tokens via cache poisoning[1][3].
- •On February 17, 2026, the attacker published malicious Cline CLI version 2.3.0 to npm, which included a postinstall script silently installing the legitimate OpenClaw AI agent globally on users' systems[1][3][4].
- •The malicious version remained live for about 8 hours until Cline team published fixed version 2.4.0 and deprecated 2.3.0, with the advisory rating severity as 'low' since OpenClaw is open-source but highlighting supply chain risks[1][2][4].
- •Security researcher Adnane Khan discovered and reported the prompt injection flaw on January 1, 2026, providing a proof-of-concept using public tools like Cacheract for cache poisoning[3].
- •This incident underscores accelerating npm supply chain attacks on AI dev tools, with prior OpenClaw 'ClawHavoc' attack in January 2026 planting malicious skills for infostealers[1][2].
🛠️ 技術深入
- •Prompt injection targeted Cline's Claude Issue Triage workflow (removed post-incident), allowing GitHub account holders to inject malicious instructions chaining to GitHub Actions cache poisoning[3].
- •Cache poisoning used tools like Cacheract to flush/evict cache, pivot to Publish Nightly Release/NPM workflows, stealing VSCE_PAT, OVSX_PAT, NPM_RELEASE_TOKEN secrets with production-level access[3].
- •Malicious npm package 2.3.0 modified only package.json to add 'postinstall': 'npm install -g openclaw@latest' lifecycle script; CLI binary dist/cli.mjs unchanged from legit 2.2.0[1].
- •Attack drew from public research like Aikido Security’s PromptPwned on AI workflow misconfigurations[3].
- •Cline CLI 2.0 features AI agent control in terminal with parallel execution, headless CI/CD, ACP editor support[5].
🔮 前景展望AI analysis grounded in cited sources
This supply chain attack via AI prompt injection in CI/CD pipelines signals heightened risks for autonomous AI agents in dev tools, potentially enabling credential theft or malware distribution; accelerates scrutiny on npm/GitHub Actions security and trust in AI-assisted automation[1][2][3].
⏳ 時間線
📎 來源 (5)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- awesomeagents.ai — Cline Npm Supply Chain Attack
- enterprisesecuritytech.com — Cline Cli Supply Chain Attack Exposes Emerging AI Agent Risks in Npm Ecosystem
- adnanthekhan.com — Clinejection
- cybersecuritynews.com — AI Dev Tool Cline
- devops.com — Cline Cli 2 0 Turns Your Terminal Into an AI Agent Control Plane
AI 週報
閱讀本週精選 AI 大事摘要 →
👉相關動態
AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: The Verge ↗
每週 AI 簡報
每週一封,可隨時退訂。


