🦞OpenClaw.report•較早收集於 15h
npm 套件被駭 安裝 OpenClaw 至 9 萬開發機
💡Supply-chain attack via npm hit 90K devs, secretly installing OpenClaw—check your setup now.
⚡ 30-Second TL;DR
有什麼變化
Cline CLI npm 套件發布權杖被竊
為什麼重要
開發工具供應鏈重大攻擊,風險無同意廣泛部署 OpenClaw。開發者須審核 CLI 工具,以因應 npm 威脅上升。
下一步行動
Run `npm audit` and scan for unauthorized OpenClaw installs on your dev machines.
誰應關注:Developers & AI Engineers
關鍵要點
- •Cline CLI npm 套件發布權杖被竊
- •悄悄在開發者機器安裝 OpenClaw
- •影響約 9 萬週使用者,持續 8 小時
🧠 深度解析
背景與延伸:來自公開資料,非原文內容。引用 10 個來源。
🔑 增強重點摘要
- •The malicious version cline@2.3.0 was downloaded approximately 4,000 times before deprecation, far below the package's typical 90,000 weekly downloads[2][8].
- •The attack exploited a prior prompt injection vulnerability in Cline disclosed by researcher Adnan Khan, whose PoC on a test repository was discovered and weaponized by the attacker[2][10].
- •OpenClaw integrates deeply with messaging apps like WhatsApp, Telegram, Slack, Discord, iMessage, and Teams, amplifying risks from its broad system access[1][3].
- •Cline maintainers responded by revoking the token, deprecating 2.3.0, releasing fixed versions 2.4.0+, and switching to OIDC provenance via GitHub Actions[2][4].
🔮 前景展望AI analysis grounded in cited sources
Security vendors will classify OpenClaw as PUA or malware
Experts like David Shipley state EDR/MDR tools must block it to counter such supply chain bypasses that evade traditional detection[1].
npm packages will mandate OIDC over long-lived tokens
This incident highlights risks of compromised tokens like clinebotorg, prompting recommendations for provenance-based publishing[4].
⏳ 時間線
2026-02
Adnan Khan discloses prompt injection vulnerability in Cline via PoC on test repo
2026-02-12
CVE-2026-25253 published detailing malicious link exploits for OpenClaw token theft
2026-02-17
Compromised npm token publishes malicious cline@2.3.0 installing OpenClaw; live for 8 hours with ~4K downloads
2026-02-20
Incident reported publicly; maintainers revoke token, deprecate version, and release fixes
📎 來源 (10)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- beauceronsecurity.com — Cline Openclaw Malware
- theregister.com — Openclaw Snuck Into Cline Package
- csoonline.com — Compromised Npm Package Silently Installs Openclaw on Developer Machines
- endorlabs.com — Supply Chain Attack Targeting Cline Installs Openclaw
- penligent.ai — Multiple Hacking Groups Exploit Openclaw Instances to Steal API Keys and Deploy Malware
- hackers-arise.com — Cve 2026 25253 How Malicious Links Can Steal Authentication Tokens and Compromise Openclaw AI Systems
- security.utoronto.ca — Openclaw Vulnerability Notification
- darkreading.com — Supply Chain Attack Openclaw Cline Users
- cybersecuritynews.com — AI Dev Tool Cline
- adnanthekhan.com — Clinejection
📰
AI 週報
閱讀本週精選 AI 大事摘要 →
👉相關動態
AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: OpenClaw.report ↗
每週 AI 簡報
每週一封,可隨時退訂。