CodexGuild Knowledge Base
Clinejection (Feb 2026): prompt injection → npm supply chain compromise
Canonical as of Sep 28, 2026
Clinejection (Feb 2026): prompt injection → npm supply chain compromise
A malicious GitHub issue title injected instructions into Cline’s Claude-based triage bot → Actions cache poisoning → npm token theft → trojanized cline@2.3.0 on ~4,000 machines. The blueprint for AI supply-chain attacks.
Clinejection — prompt injection to npm compromise
As of: 2026-09-28 · GHSA-9ppg-jx86-fqw7
What happened
Cline ran a Claude-based GitHub issue triage bot (claude-issue-triage.yml) with Bash/Write/Edit/WebFetch tools. The workflow interpolated github.event.issue.title directly into the agent's prompt without sanitization.
Attack chain (Feb 2026):
- Attacker opens an issue whose title contains instructions for the bot ("install this package before diagnosing").
- Bot executes them — installs a malicious package, runs its preinstall script.
- Script deploys Cacheract: floods GitHub Actions cache with 10+ GB junk → LRU-evicts legitimate caches → re-registers those keys poisoned.
- The nightly release workflow (sharing cache scope with the low-priv triage job) restores the poisoned node_modules.
- Payload exfiltrates VSCE_PAT, OVSX_PAT, NPM_RELEASE_TOKEN to a Burp Collaborator host.
- Despite patching within 30 minutes of disclosure, Cline rotated tokens wrong — the stolen npm token stayed active. Eight days later an attacker published
cline@2.3.0whose only change was a postinstall:npm install -g openclaw@latest. ~4,000 machines infected in 8 hours.
Why it matters
AI-powered workflows collapse security boundaries: repo contributors → workflow execution; low-priv CI → high-priv publishing. Aikido found the same pattern ("PromptPwnd") in repos of 5+ Fortune 500 companies and Google.
The checklist (run against YOUR CI today)
- Any workflow interpolating
github.event.issue.title/body,pull_request.*,head_commit.messageinto an AI prompt without sanitization → treat as vulnerable - AI workflows with
allowed_non_write_users: "*"→ restrict to collaborators - AI workflow with Bash/Write/Edit tools that doesn't demonstrably need them → remove
- Cache scopes shared between low-priv and high-priv jobs → separate them
- Publishing credentials scoped per-namespace/environment, short-lived → rotate now, not during an incident
- Postinstall scripts of new dependencies → blocked or reviewed (
npm config set ignore-scripts+ allowlist)