Image for Article: Supply Chain Attack Secretly Installs OpenClaw for Cline Users

Article Details

Title
Article: Supply Chain Attack Secretly Installs OpenClaw for Cline Users
Impact Score
5 / 10
AI Summary (Processed Content)

A supply chain attack compromised the npm package for the AI coding tool Cline, causing version 2.3.0 to secretly install a program called OpenClaw on users' systems. The attack exploited a previously disclosed vulnerability to steal a publication token and was downloaded over 4,000 times before being removed. While OpenClaw is not traditional malware, it poses significant risk by establishing a persistent background process with broad system permissions. The main topics covered are the supply chain attack mechanism, the nature of the OpenClaw payload, and the security vulnerabilities in the Cline framework that enabled the incident.

Original URL
https://www.darkreading.com/application-security/supply-chain-attack-openclaw-cline-users
Source Feed
darkreading
Published Date
2026-02-19 22:33
Fetched Date
2026-03-04 13:42
Processed Date
2026-03-04 13:49
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content