LIVE NEWS
  • Calls for Global Digital Estate Standard as Fraud Risk Grows
  • An ode to craftsmanship in software development
  • Global economy must stop pandering to ‘frivolous desires of ultra-rich’, says UN expert | Environment
  • Some Middle East Flights Resume but Confusion Reigns From Iran Strikes
  • Clinton Deposition Videos Released in Epstein Investigation
  • Elevance stock tumbles as CMS may halt Medicare enrollment
  • Wild spaces for butterflies to be created in Glasgow
  • You can now adjust how your caller card looks for calls on Android phones
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Supply Chain Attack Secretly Installs OpenClaw for Cline Users
Cybersecurity

Supply Chain Attack Secretly Installs OpenClaw for Cline Users

primereportsBy primereportsFebruary 23, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Supply Chain Attack Secretly Installs OpenClaw for Cline Users
Share
Facebook Twitter LinkedIn Pinterest Email


The rapid spread of OpenClaw wasn’t going fast enough for someone.

Cybersecurity vendors this week noticed an odd trend when the npm package for version 2.3.0 of Cline, a widely used open source AI coding tool, began installing an apparent stowaway program: OpenClaw. For approximately eight hours, users who downloaded Cline received a poisoned version of the tool that, while not carrying traditional malware, still made unauthorized installations on their systems.

It’s unclear who perpetrated this odd supply chain attack, and what the ultimate motivation is beyond forced installations of OpenClaw. But the attack marks the latest red flag for the fast-growing AI framework, which security researchers have expressed concerns about since its explosion onto the technology landscape last month.

A PoC Leads to a Poisoned NPM Package

The supply chain attack stemmed from a vulnerability disclosed earlier this month by security researcher Adnan Khan. Exploitation of the vulnerability, which had no assigned CVE at press time, can lead to an attacker obtaining secrets such as release tokens.

Related:Attackers Use New Tool to Scan for React2Shell Exposure

“Between Dec. 21, 2025, and Feb. 9, 2026, a prompt injection vulnerability in Cline’s (now removed) Claude Issue Triage workflow allowed any attacker with a GitHub account to compromise production Cline releases on both the Visual Studio Code Marketplace and OpenVSX and publish malware to millions of developers!” Khan wrote in a blog post.

Khan said his attempts to contact Cline were initially “fruitless,” and the company quickly patched the vulnerability shortly after his research was published. Unfortunately, someone took advantage of Khan’s research, stole an npm publish token, and tricked the latest version of Cline into also installing OpenClaw.

Henrik Plate, security researcher with Endor Labs, explained in a blog post that version 2.3.0 of the Cline CLI npm package used a post-install hook to silently download OpenClaw to the same system. While the impact is considered low because OpenClaw isn’t malicious, he noted that “this event emphasizes the need for package maintainers to not only enable trusted publishing, but also disable publication through traditional tokens — and for package users to pay attention to the presence (and sudden absence) of corresponding attestations.”

In an update to his blog post, Khan stressed that he was not behind the supply chain attack and that he didn’t conduct testing of his proof-of-concept (PoC) exploit on Cline’s repository. “I conducted my PoC on a mirror of Cline to confirm the prompt injection vulnerability. A different actor found my PoC on my test repository and used it to directly attack Cline and obtain the publication credentials,” he wrote.

Related:‘God-Like’ Attack Machines: AI Agents Ignore Security Policies

Cline published an advisory on GitHub and released version 2.4.0 while removing the previous, tainted npm package. “The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions,” the company said. 

OpenClaw Not Malicious, But Risky

StepSecurity said the compromised Cline package was downloaded approximately 4,000 times over an eight-hour stretch before version 2.3.0 was deprecated. And while the short-lived supply chain attack didn’t deploy malware, that doesn’t mean it didn’t present serious risk.

Sai Likhith Paradarami, software engineer with StepSecurity, explained in a blog post that OpenClaw is a “dangerous payload” because it had broad permissions as well as full disk access on a system in order to execute tasks on the user’s behalf. OpenClaw also establishes a persistent Gateway daemon that runs quietly in the background as a WebSocket server.

“This design makes it an exceptionally high-value implant for an attacker,” Paradarami, wrote, adding that a silently installed version of OpenClaw could give a threat actor a persistent foothold on a targeted system with the ability to steals secrets and credentials as well as tamper with development environments. 

Related:Lessons From AI Hacking: Every Model, Every Layer Is Risky

Along with updating their systems to version 2.4.0, Paradarami urged Cline users to review their environments for any unwanted installations of OpenClaw.



Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleInfosys AI implementation framework offers business leaders guidance
Next Article Mexican Forces Kill ‘El Mencho,’ Nation’s Most-Wanted Cartel Boss – The New York Times
primereports
  • Website

Related Posts

Cybersecurity

Calls for Global Digital Estate Standard as Fraud Risk Grows

March 4, 2026
Cybersecurity

Samsung Unpacked 2026 live blog: Updates on Galaxy S26 Ultra, preorder deals, and pricing

February 25, 2026
Cybersecurity

Marquis sues SonicWall over backup breach that led to ransomware attack

February 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20255 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Artificial Intelligence
  • Popular Now
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Calls for Global Digital Estate Standard as Fraud Risk Grows
  • An ode to craftsmanship in software development
  • Global economy must stop pandering to ‘frivolous desires of ultra-rich’, says UN expert | Environment
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.