🦞較早收集於 15h

npm 套件被駭 安裝 OpenClaw 至 9 萬開發機

PostLinkedIn
🦞閱讀原文: OpenClaw.report

💡Supply-chain attack via npm hit 90K devs, secretly installing OpenClaw—check your setup now.

⚡ 30-Second TL;DR

有什麼變化

Cline CLI npm 套件發布權杖被竊

為什麼重要

開發工具供應鏈重大攻擊,風險無同意廣泛部署 OpenClaw。開發者須審核 CLI 工具,以因應 npm 威脅上升。

下一步行動

Run `npm audit` and scan for unauthorized OpenClaw installs on your dev machines.

誰應關注:Developers & AI Engineers

關鍵要點

  • Cline CLI npm 套件發布權杖被竊
  • 悄悄在開發者機器安裝 OpenClaw
  • 影響約 9 萬週使用者,持續 8 小時

🧠 深度解析

背景與延伸:來自公開資料,非原文內容。引用 10 個來源。

🔑 增強重點摘要

  • The malicious version cline@2.3.0 was downloaded approximately 4,000 times before deprecation, far below the package's typical 90,000 weekly downloads[2][8].
  • The attack exploited a prior prompt injection vulnerability in Cline disclosed by researcher Adnan Khan, whose PoC on a test repository was discovered and weaponized by the attacker[2][10].
  • OpenClaw integrates deeply with messaging apps like WhatsApp, Telegram, Slack, Discord, iMessage, and Teams, amplifying risks from its broad system access[1][3].
  • Cline maintainers responded by revoking the token, deprecating 2.3.0, releasing fixed versions 2.4.0+, and switching to OIDC provenance via GitHub Actions[2][4].

🔮 前景展望AI analysis grounded in cited sources

Security vendors will classify OpenClaw as PUA or malware
Experts like David Shipley state EDR/MDR tools must block it to counter such supply chain bypasses that evade traditional detection[1].
npm packages will mandate OIDC over long-lived tokens
This incident highlights risks of compromised tokens like clinebotorg, prompting recommendations for provenance-based publishing[4].
AI agents face heightened scrutiny for prompt injection
The attack chained a known Cline prompt injection vuln, underscoring persistent risks in agentic apps with autonomous actions[2][3].

時間線

2026-02
Adnan Khan discloses prompt injection vulnerability in Cline via PoC on test repo
2026-02-12
CVE-2026-25253 published detailing malicious link exploits for OpenClaw token theft
2026-02-17
Compromised npm token publishes malicious cline@2.3.0 installing OpenClaw; live for 8 hours with ~4K downloads
2026-02-20
Incident reported publicly; maintainers revoke token, deprecate version, and release fixes
📰

AI 週報

閱讀本週精選 AI 大事摘要 →

👉相關動態

AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: OpenClaw.report

這是摘要,不是原文。去看原站,或訂閱每週簡報。

每週 AI 簡報

每週一封,可隨時退訂。