Switch language한국어
Back to the list

Clinejection: When Your AI Coding Tool Became the Weapon

TL;DR AI

Key summary

2 min read
  1. An attacker chained an indirect prompt injection against Cline’s GitHub issue triage bot with GitHub Actions cache poisoning.

  2. The attack led to theft of an npm automation token and an unauthorized package publish containing a rogue agent.

  3. The malicious version briefly reached thousands of machines before the package was removed.

  4. The case shows how AI-enabled developer workflows can become supply-chain risks when trusted inputs and overprivileged secrets are combined.

Read the original