Cline CLI 2.3.0 was published with a stolen npm token, installing OpenClaw in an 8-hour attack affecting ~4,000 downloads.
The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.
Cline CEO Saoud Rizwan said his open source AI coding tool started off as a side project for Anthropic's "Build with Claude" hackathon. Software developers love using AI. So much so that they’re ...