Attackers pushed a poisoned cline@2.3.0 to npm using a stolen publish token. Its postinstall installed OpenClaw globally.
An AI triage bot let a malicious issue title trick Claude into running commands on a GitHub Actions runner. It wrote a poisoned actions/cache entry.
The nightly release restored the poisoned node_modules. That exfiltrated NPM_RELEASE_TOKEN and enabled an unauthorized npm publish without provenance.










