Supply Chain Attack Secretly Installs OpenClaw for Cline Users
from DarkReading 19 February indexed on 20 February 2026 4:01The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.
Read more.
