Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

February 17, 2026

An unknown actor reportedly exploited prompt injection in Cline’s Claude-powered GitHub issue-triage workflow and a GitHub Actions cache-poisoning path to obtain publication credentials. On February 17, 2026, a still-valid npm token was used to publish unauthorized cline@2.3.0, which installed OpenClaw without user intent. Cline said OpenClaw was non-malicious; it deprecated the release and revoked the token that day, while reporting that it found no evidence of user-data exposure.

Matched TAIM controls

Suggested mapping from embedding similarity (not a formal assessment). Browse all TAIM controls

Alleged deployer
cline-bot-inc., ai-agent-system-deployers, threat-actors
Alleged developer
anthropic, ai-agent-system-developers
Alleged harmed parties
cline-bot-inc., cline-cli-users, software-developers

AI governance case studies

For forensic AI governance failure analysis (TAIMScore™ case studies), browse Human Signal’s Failure Files™.

Source

Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/1680

Data source

Incident data is from the AI Incident Database (AIID).

When citing the database as a whole, please use:

McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.

Pre-print on arXiv · Database snapshots & citation guide

We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.