Theregister Cline CLI npm Package Compromised, Installs OpenClaw on Developer Machines
Article Content
Browse articles
The Cline CLI npm package was compromised on February 17, 2026, allowing an unauthorized party to publish a malicious update (version 2.3.0) that secretly installs OpenClaw on users' machines. This incident affected developers who downloaded the package, with over 4,000 downloads before the malicious version was removed. The attack exploited a compromised publish token, granting access for approximately 8 hours.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
Timeline
2026-02-17
Unauthorized party compromised Cline CLI npm package
2026-02-17
Malicious version 2.3.0 published on npm
2026-02-17
Malicious package downloaded over 4,000 times
2026-02-20
Malicious version removed from npm
More articles in this cluster (8)
Following this threat?
Track Cline in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
SSRF Vulnerability in Sentry MCP Server Exposes Security Risks On July 12, 2026, researcher cccccccti disclosed a Server-Side Request Forgery (SSRF) vulnerability in the raw_sentry_api component of ddfourtwo/sentry-selfhosted-mcp, tracked as CVE-2026-81421. This vulnerability allows attackers to force Axios to call arbitrary endpoints, with a public exploit already available. As…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…