The open-source AI coding assistant Cline CLI was compromised earlier this week in a supply chain attack that secretly installed OpenClaw on developers' machines. An unauthorized party used a compromised token to publish an update to Cline CLI on its npm registry, which then installed OpenClaw on users' computers when they installed [email protected]. This incident occurred during an approximately 8-hour window on February 17, as reported by The Register.The attack involved an unauthorized party gaining access to Cline CLI's npm package via a compromised token. This allowed them to publish version 2.3.0, which included an unauthorized installation of the OpenClaw AI agent platform. While OpenClaw itself is not malicious, its installation was unintended and occurred without user knowledge.Cline maintainers have since revoked the compromised token and implemented OIDC provenance via GitHub Actions for publishing. The compromised version was downloaded approximately 4,000 times before being deprecated. Microsoft observed a noticeable uptick in OpenClaw installations initiated by the Cline CLI script during the incident.Source: The Register
Supply chain, DevOps, AI/ML
Open source AI coding assistant Cline CLI targeted in supply chain attack

(Adobe Stock)
An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



