What happened
An unknown actor exploited prompt injection in Cline's GitHub Actions workflows to steal npm publish tokens via cache poisoning. The attacker then published [email protected] with a postinstall script that silently downloaded and installed OpenClaw on developer machines during `npm install cline`.