david celis @davidcelis@xoxo.zone3/5/2026, 6:21:48 PMPubliclolhttps://grith.ai/blog/clinejection-when-your-ai-tool-installs-anotherA GitHub Issue Title Compromised 4,000 Developer MachinesA prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.grith.ai