Clinejection: When Your AI Coding Tool Became the Weapon

TL;DR AI
2 min readKey summary
An attacker chained an indirect prompt injection against Cline’s GitHub issue triage bot with GitHub Actions cache poisoning.
The attack led to theft of an npm automation token and an unauthorized package publish containing a rogue agent.
The malicious version briefly reached thousands of machines before the package was removed.
The case shows how AI-enabled developer workflows can become supply-chain risks when trusted inputs and overprivileged secrets are combined.
