Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. cline
  4. ›
  5. GHSA-9ppg-jx86-fqw7

GHSA-9ppg-jx86-fqw7: Unauthorized npm publish of cline@2.3.0 with modified postinstall script

February 19, 2026

On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM registry: cline@2.3.0. The published package contains a modified package.json with an added postinstall script: "postinstall": "npm install -g openclaw@latest" This causes openclaw (an unrelated, non-malicious open source package) to be globally installed when cline@2.3.0 is installed. No other files were modified – the CLI binary (dist/cli.mjs) and all other package contents are identical to the legitimate cline@2.2.3 release. A corrected version (2.4.0) was published at 11:23 AM PT and 2.3.0 was deprecated at 11:30 AM PT. The compromised token has been revoked and npm publishing now uses OIDC provenance via GitHub Actions.

References

  • github.com/advisories/GHSA-9ppg-jx86-fqw7
  • github.com/cline/cline
  • github.com/cline/cline/security/advisories/GHSA-9ppg-jx86-fqw7

Code Behaviors & Features

Detect and mitigate GHSA-9ppg-jx86-fqw7 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 2.3.0 before 2.4.0, version 2.3.0

Fixed versions

  • 2.4.0

Solution

Upgrade to version 2.4.0 or above.

Source file

npm/cline/GHSA-9ppg-jx86-fqw7.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 20 Feb 2026 12:20:25 +0000.