an unauthorized party used a compromised npm publish token to publish cline@2.3.0 to npm. The published package contained a single modification: an added postinstall script that globally installs openclaw… The CLI binary and all other package contents were byte-identical to the previous release.

cline.bot/blog/post-mortem-una

0

If you have a fediverse account, you can quote this note from your own instance. Search https://23.social/users/leyrer/statuses/116199589950377867 on your instance and quote it. (Note that quoting is not supported in Mastodon.)