an unauthorized party used a compromised npm publish token to publish cline@2.3.0 to npm. The published package contained a single modification: an added postinstall script that globally installs openclaw… The CLI binary and all other package contents were byte-identical to the previous release.
https://cline.bot/blog/post-mortem-unauthorized-cline-cli-npm
