GitHub issue title compromises npm package via triage bot
2026-03-05 23:04:14.523413+01 by Dan Lyke 0 comments
Wheee: A GitHub Issue Title Compromised 4,000 Developer Machines
For the next eight hours, every developer who installed or updated Cline got OpenClaw - a separate AI agent with full system access - installed globally on their machine without consent. Approximately 4,000 downloads occurred before the package was pulled1.
The interesting part is not the payload. It is how the attacker got the npm token in the first place: by injecting a prompt into a GitHub issue title, which an AI triage bot read, interpreted as an instruction, and executed.