LIVE NEWS
  • Trinidad and Tobago police uncover 56 bodies, mostly children, at cemetery | Crime News
  • The best TV antennas to buy in 2024
  • Look beyond Trump for the real story on US climate action
  • Obama meets Mamdani in New York City before reading to preschoolers
  • How Trump is pushing psychedelics reform through the health agencies
  • Now is your last chance to grab our EXCLUSIVE Surfshark deal — year-low prices with 4 months extra protection included
  • Middle East crisis live: ships report attacks as Iran closes strait of Hormuz; Trump reportedly convenes Situation Room meeting | US-Israel war on Iran
  • 50,640 People Affected After Hackers Hit Healthcare Firm, Stealing Personal, Financial and Medical Data
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»Supply Chain Attack Secretly Installs OpenClaw for Cline Users
Cybersecurity

Supply Chain Attack Secretly Installs OpenClaw for Cline Users

primereportsBy primereportsFebruary 23, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Supply Chain Attack Secretly Installs OpenClaw for Cline Users
Share
Facebook Twitter LinkedIn Pinterest Email


The rapid spread of OpenClaw wasn’t going fast enough for someone.

Cybersecurity vendors this week noticed an odd trend when the npm package for version 2.3.0 of Cline, a widely used open source AI coding tool, began installing an apparent stowaway program: OpenClaw. For approximately eight hours, users who downloaded Cline received a poisoned version of the tool that, while not carrying traditional malware, still made unauthorized installations on their systems.

It’s unclear who perpetrated this odd supply chain attack, and what the ultimate motivation is beyond forced installations of OpenClaw. But the attack marks the latest red flag for the fast-growing AI framework, which security researchers have expressed concerns about since its explosion onto the technology landscape last month.

A PoC Leads to a Poisoned NPM Package

The supply chain attack stemmed from a vulnerability disclosed earlier this month by security researcher Adnan Khan. Exploitation of the vulnerability, which had no assigned CVE at press time, can lead to an attacker obtaining secrets such as release tokens.

Related:Attackers Use New Tool to Scan for React2Shell Exposure

“Between Dec. 21, 2025, and Feb. 9, 2026, a prompt injection vulnerability in Cline’s (now removed) Claude Issue Triage workflow allowed any attacker with a GitHub account to compromise production Cline releases on both the Visual Studio Code Marketplace and OpenVSX and publish malware to millions of developers!” Khan wrote in a blog post.

Khan said his attempts to contact Cline were initially “fruitless,” and the company quickly patched the vulnerability shortly after his research was published. Unfortunately, someone took advantage of Khan’s research, stole an npm publish token, and tricked the latest version of Cline into also installing OpenClaw.

Henrik Plate, security researcher with Endor Labs, explained in a blog post that version 2.3.0 of the Cline CLI npm package used a post-install hook to silently download OpenClaw to the same system. While the impact is considered low because OpenClaw isn’t malicious, he noted that “this event emphasizes the need for package maintainers to not only enable trusted publishing, but also disable publication through traditional tokens — and for package users to pay attention to the presence (and sudden absence) of corresponding attestations.”

In an update to his blog post, Khan stressed that he was not behind the supply chain attack and that he didn’t conduct testing of his proof-of-concept (PoC) exploit on Cline’s repository. “I conducted my PoC on a mirror of Cline to confirm the prompt injection vulnerability. A different actor found my PoC on my test repository and used it to directly attack Cline and obtain the publication credentials,” he wrote.

Related:‘God-Like’ Attack Machines: AI Agents Ignore Security Policies

Cline published an advisory on GitHub and released version 2.4.0 while removing the previous, tainted npm package. “The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions,” the company said. 

OpenClaw Not Malicious, But Risky

StepSecurity said the compromised Cline package was downloaded approximately 4,000 times over an eight-hour stretch before version 2.3.0 was deprecated. And while the short-lived supply chain attack didn’t deploy malware, that doesn’t mean it didn’t present serious risk.

Sai Likhith Paradarami, software engineer with StepSecurity, explained in a blog post that OpenClaw is a “dangerous payload” because it had broad permissions as well as full disk access on a system in order to execute tasks on the user’s behalf. OpenClaw also establishes a persistent Gateway daemon that runs quietly in the background as a WebSocket server.

“This design makes it an exceptionally high-value implant for an attacker,” Paradarami, wrote, adding that a silently installed version of OpenClaw could give a threat actor a persistent foothold on a targeted system with the ability to steals secrets and credentials as well as tamper with development environments. 

Related:Lessons From AI Hacking: Every Model, Every Layer Is Risky

Along with updating their systems to version 2.4.0, Paradarami urged Cline users to review their environments for any unwanted installations of OpenClaw.



Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleInfosys AI implementation framework offers business leaders guidance
Next Article Mexican Forces Kill ‘El Mencho,’ Nation’s Most-Wanted Cartel Boss – The New York Times
primereports
  • Website

Related Posts

Cybersecurity

[Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise Data

April 18, 2026
Cybersecurity

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

April 18, 2026
Cybersecurity

Google wipes out 602 million scam ads with Gemini on duty

April 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20258 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • Trinidad and Tobago police uncover 56 bodies, mostly children, at cemetery | Crime News
  • The best TV antennas to buy in 2024
  • Look beyond Trump for the real story on US climate action
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.