Skip to content

Add case: Cline CLI unauthorized npm publish (2026)#15

Closed
Y0uYuGe wants to merge 2 commits into
Narwhal-Lab:mainfrom
Y0uYuGe:add-case-2026-cline-cli-npm-openclaw-install
Closed

Add case: Cline CLI unauthorized npm publish (2026)#15
Y0uYuGe wants to merge 2 commits into
Narwhal-Lab:mainfrom
Y0uYuGe:add-case-2026-cline-cli-npm-openclaw-install

Conversation

@Y0uYuGe
Copy link
Copy Markdown
Contributor

@Y0uYuGe Y0uYuGe commented May 18, 2026

Closes #11

Summary

  • Adds a verified supply-chain case for the unauthorized cline@2.3.0 npm publish that installed OpenClaw.
  • Documents Cline's official post-mortem, GHSA-9ppg-jx86-fqw7, impact, and mitigations.
  • Regenerates case index and chart artifacts for this single-case PR.

Validation

  • python3 scripts/validate_cases.py
  • python3 scripts/render_index.py
  • New case reference links checked with scripts.validate_cases.check_url

Note

This PR intentionally contains one case only. Other case PRs are separate and may need rebase after merge order is decided.

@Y0uYuGe
Copy link
Copy Markdown
Contributor Author

Y0uYuGe commented May 18, 2026

Superseded by #17, which combines the remaining Gemini, Cursor, and Cline cases after #16 was merged.

@Y0uYuGe Y0uYuGe closed this May 18, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Submit case: Cline CLI unauthorized npm publish (2026)

1 participant