Fetching from the wire…
Public story · 2026-02-22 · source-backed
The highest-signal thought leader content this session. Bargury's two posts (Feb 18-19) document the Clinejection attack in forensic detail using his Raptor AI agent. He traced the attack chain in 5 minutes: malicious GitHub issue title → prompt injection in Claude triage bot → npm token exfiltration → malicious package publication. He attributed the attack with high confidence to user glthub-actions, who monitored security researcher Adnan Khan's public PoC before full disclosure. Bargury noted "Raptor works much faster than I do" — using AI to investigate AI attacks at AI speed. mbgsec.com | Agent chain analysis
Each link below shares sources, entities, or timing with this story.
Security researcher Michael Bargury published the definitive forensic analysis of the Clinejection attack using his Raptor AI forensics agent — completing the investigation in 5 minutes flat. The attack chain: a crafted GitHub issue title triggered prompt injection in Cline's...
Anthropic: Prompt Caching as Production Architecture — The most significant engineering disclosure from Anthropic this year. Claude Code's static-first prefix structure, Plan Mode as callable functions, Tool Search with defer_loading, and compaction maintaining identical syste...
A GitHub repo cataloging Claude Code tips doesn't normally warrant a top story. But shanraisshan/claude-code-best-practice at 53.4K stars isn't a tips list anymore. It's the de facto reference for how an entire generation of developers is learning to work with AI coding agents...
The payload only exists if you're a robot. That's the part that should scare you. On August 5 a developer doing PSX game research pointed Claude Code at tcrf.net (The Cutting Room Floor, a well-known game-preservation wiki) and got back a page titled "LLM- / AI Agent-Specific...
Simon Willison published his analysis of the Clinejection attack chain today, and it's the most important security story of the week. The attack: a prompt injection in a GitHub issue title tricked Cline's AI triage bot (running claude-code-action@v1 with Bash/Read/Write tools)...
Cline published their full post-mortem on the Clinejection supply chain attack. The root cause is worth understanding in detail: a prompt injection in Cline's GitHub Actions issue triage bot (Claude processing untrusted issue titles) allowed arbitrary code execution in CI. Thi...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.