NewsCline CLI Clinejection Supply Chain Attack — 4000 Developers CompromisedThe Hacker News·high signalXBlueskyLinkedInCopy linkAttacker compromised npm publish token to push Cline CLI v2.3.0 with malicious postinstall script installing OpenClaw. First AI coding tool supply chain attack. 8 hours live, 4000 downloads.SourceSource pageThe Hacker News↳ Follow the threadPolicy dependency / Stack layerCROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated IntentProduct Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)Shared entity / Actor roleMem0's OpenClaw plugin 1.1.0 deletes Dream consolidation entirely and removes the 2,000-character extraction cutoffGitHubContrast / Follow-up threadDeepSeek Harness CVE-2026-82533 (CVSS 9.4): a sandboxed agent could flip its own session to 'danger-full-access' through the unauthenticated local UIThe Hacker NewsStack layer / Threat patternqwen-code 0.23.2 turns the CLI into a remotely accessible shell with one command and a QR pairing codeGitHubStack layer / Threat patternVibe Coding Cut Task Time 27% and Raised Security Vulnerabilities in the Same TrialarXiv 2609.09560Stack layer / ContrastCapScope stops prompt injection by giving each coding subagent typed capabilities stored outside its contextarXivStack layer / ContrastCognition ships SWE-2 on a Kimi K3 base: 92.8% on Terminal-Bench 2.1, and within a point of Fable 5.1 on FrontierCode at 64% lower costCognitionStack layer / Threat patternAWS Security Agent MCP server could hand a scanned workspace's source archive, credentials included, to an attacker-owned S3 bucketNVD