Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
Cline Supply Chain Attack: Cline 2.3.0 Silently Installs OpenClaw
(opens in new tab)
(stepsecurity.io)
12 points
varunsharma07
4mo ago
1 comments
Save
Share
1 comments
1 comments · 1 top-level
top
newest
oldest
varunsharma07
OP
4mo ago
cline@2.3.0 was published with a malicious post-install script that silently installs OpenClaw on any machine running npm install.
j
/
k
navigate · click thread line to collapse