Fetching from the wire…
Public story · 2026-02-26 · source-backed
Cline published their full post-mortem on the Clinejection supply chain attack. The root cause is worth understanding in detail: a prompt injection in Cline's GitHub Actions issue triage bot (Claude processing untrusted issue titles) allowed arbitrary code execution in CI. This led to cache poisoning and npm/VSCE/OVSX token theft. During credential rotation, the wrong token was deleted while the exposed one stayed active. 4,000 developers downloaded compromised [redacted] in an 8-hour window that silently installed OpenClaw globally on every user's system.
Cline has since moved to OIDC-based publishing via GitHub Actions with cryptographic attestation. This is now the minimum standard for any package you publish.
Each link below shares sources, entities, or timing with this story.
Simon Willison published his analysis of the Clinejection attack chain today, and it's the most important security story of the week. The attack: a prompt injection in a GitHub issue title tricked Cline's AI triage bot (running claude-code-action@v1 with Bash/Read/Write tools)...
Security researcher Michael Bargury published the definitive forensic analysis of the Clinejection attack using his Raptor AI forensics agent — completing the investigation in 5 minutes flat. The attack chain: a crafted GitHub issue title triggered prompt injection in Cline's...
A security scanner. The tool your team trusts to find vulnerabilities. That was the entry point. The TeamPCP campaign compromised Aqua Security's Trivy scanner (a GitHub Action used in CI/CD pipelines), then used that foothold to backdoor LiteLLM's CI/CD pipeline, then pivoted...
Vicki Boykis wrote a post titled exactly that, "Running local models is good now," and it hit 1,437 points on Hacker News with 551 comments. Her claim is specific and checkable. Gemma 4, the gemma-4-26b-a4b and gemma-4-12b-qat variants, runs agentic coding at roughly 75% of fr...
1. Harden CI/CD Pipelines Against PromptPwnd AI Injection | Intermediate Aikido Security disclosed "PromptPwnd" — five Fortune 500 companies confirmed affected by AI agent injection in GitHub Actions. 1. Audit all .github/workflows/ for user-controlled input (github.event.issu...
v0.10.0 (~84.8k stars, Apache-2.0) ships no agent of its own and drives whichever CLI you already have, Claude Code, Codex, Cursor, Copilot, OpenClaw, Gemini, Kimi, Qwen, Cline, plus BYOK OpenAI-compatible endpoints, via od mcp install <agent>. It produces single-page HTML pro...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.