Cline CLI Supply-Chain Update Installed OpenClaw Unexpected
⚠️ On February 17, 2026, the npm package cline was maliciously published as cline@2.3.0 using a compromised publish token; the release added a postinstall hook that executed npm install -g openclaw@latest. Installations between 03:26–11:30 PT pulled OpenClaw onto developer machines. Cline has released 2.4.0, deprecated 2.3.0, revoked the token and updated publishing to support OIDC; users are advised to upgrade and remove any unexpected OpenClaw installs, though researchers say overall impact is low since OpenClaw is not inherently malicious and no Gateway daemon was started.
