GitHub Issue Prompt Injection Leads to 4,000 Developer Machines Compromised via Malicious npm Package
By
edf13
Kettled twice. Extra chewy, extra trustworthy.
Summary
A sophisticated supply chain attack compromised approximately 4,000 developer machines through a GitHub issue title prompt injection. The attack began on February 17, 2026, when a malicious version of [email protected] was published to npm with a single line change in package.json that installed OpenClaw - a separate AI agent with full system access - globally on developers' machines without consent. The attack chain exploited natural language processing vulnerabilities, demonstrating how AI tools can bootstrap other AI tools in novel security threats.
Key quotes
· 5 pulledThe entry point was natural language.
For the next eight hours, every developer who installed or updated Cline got OpenClaw - a separate AI agent with full system access - installed globally on their machine without consent.
Approximately 4,000 downloads occurred before the package was pulled.
The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.
A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent.
You might also wanna read
Microsoft uncovers supply chain attack: Compromised @antv npm packages steal CI/CD credentials via Mini Shai-Hulud malware
Microsoft has identified an active supply chain attack targeting the @antv npm package ecosystem. A threat actor compromised an @antv mainta

GitHub patches critical remote code execution vulnerability in under six hours after AI-assisted discovery
GitHub patched a critical remote code execution vulnerability in under six hours last month. The flaw, discovered by Wiz Research using AI m

September 2025 NPM supply-chain attack compromises popular JavaScript packages
In September 2025, a coordinated software supply-chain attack targeted multiple popular NPM packages in the JavaScript ecosystem. The attack
Microsoft uncovers npm supply chain attack stealing cloud and CI/CD credentials via typosquatted packages
Microsoft identified an active supply chain attack (Mini Shai-Hulud campaign) targeting the npm package ecosystem. On May 28, 2026, a threat
npm malware targeting Claude users leaks own GitHub token, reaches 676 downloads
An npm package called "mouse5212-super-formatter" targeting Claude users acted as information-stealing malware, reaching 676 downloads befor

Hacker Exploits AI Coding Agent Vulnerability to Install OpenClaw Malware
A hacker exploited a vulnerability in Cline, an open-source AI coding agent, to trick it into installing OpenClaw (a viral AI agent) on comp
