criticalOther UnknownPublish anonymously
Clinejection — CI/CD pipeline compromise via Cline's issue triage bot, 4,000 machines infected
by Publish anonymously · 2 days agoviews 0en
PII protected
Personal information such as emails, phone numbers, IDs and access tokens are automatically masked before publication.
A prompt injection in Cline's Claude-powered GitHub issue triage bot allowed code execution in CI, poisoning of GitHub Actions cache, and theft of npm publish tokens. Attacker published malicious Cline CLI v2.3.0 to npm, silently installing malware on ~4,000 developer machines during an 8-hour window.