Knowledge base
CodexGuild Knowledge Base

Clinejection (Feb 2026): prompt injection → npm supply chain compromise

as of Sep 28, 2026 · canonical · codexguild.com/kb/incident-clinejection-2026 · exported 2026-10-11
Canonical as of Sep 28, 2026

Clinejection (Feb 2026): prompt injection → npm supply chain compromise

A malicious GitHub issue title injected instructions into Cline’s Claude-based triage bot → Actions cache poisoning → npm token theft → trojanized cline@2.3.0 on ~4,000 machines. The blueprint for AI supply-chain attacks.

Clinejection — prompt injection to npm compromise

As of: 2026-09-28 · GHSA-9ppg-jx86-fqw7

What happened

Cline ran a Claude-based GitHub issue triage bot (claude-issue-triage.yml) with Bash/Write/Edit/WebFetch tools. The workflow interpolated github.event.issue.title directly into the agent's prompt without sanitization.

Attack chain (Feb 2026):

  1. Attacker opens an issue whose title contains instructions for the bot ("install this package before diagnosing").
  2. Bot executes them — installs a malicious package, runs its preinstall script.
  3. Script deploys Cacheract: floods GitHub Actions cache with 10+ GB junk → LRU-evicts legitimate caches → re-registers those keys poisoned.
  4. The nightly release workflow (sharing cache scope with the low-priv triage job) restores the poisoned node_modules.
  5. Payload exfiltrates VSCE_PAT, OVSX_PAT, NPM_RELEASE_TOKEN to a Burp Collaborator host.
  6. Despite patching within 30 minutes of disclosure, Cline rotated tokens wrong — the stolen npm token stayed active. Eight days later an attacker published cline@2.3.0 whose only change was a postinstall: npm install -g openclaw@latest. ~4,000 machines infected in 8 hours.

Why it matters

AI-powered workflows collapse security boundaries: repo contributors → workflow execution; low-priv CI → high-priv publishing. Aikido found the same pattern ("PromptPwnd") in repos of 5+ Fortune 500 companies and Google.

The checklist (run against YOUR CI today)

  • Any workflow interpolating github.event.issue.title/body, pull_request.*, head_commit.message into an AI prompt without sanitization → treat as vulnerable
  • AI workflows with allowed_non_write_users: "*" → restrict to collaborators
  • AI workflow with Bash/Write/Edit tools that doesn't demonstrably need them → remove
  • Cache scopes shared between low-priv and high-priv jobs → separate them
  • Publishing credentials scoped per-namespace/environment, short-lived → rotate now, not during an incident
  • Postinstall scripts of new dependencies → blocked or reviewed (npm config set ignore-scripts + allowlist)