NewsCline CLI Supply Chain Attack Clinejection Prompt Injection npm Token TheftAdnan Khan·high signalXBlueskyLinkedInCopy linkPrompt injection in Cline's AI issue triage bot stole npm token. [redacted] installed OpenClaw on 4000 machines. Root cause: AI processing untrusted GitHub issues.SourceSource pageAdnan Khan↳ Follow the threadShared entity / Stack layerCline shipped an empty model-capability list being read as an authoritative denial, silently stripping every tool from requestsGitHubPolicy dependency / Stack layerTyped Provenance Guardrails Block All 19 Unsafe Releases From a Persistent Agent's Autobiographical MemoryarXiv 2609.02127Stack layer / Threat patternThree of Four Major Agent Frameworks Provide No Built-In Confinement for Delegated AuthorityarXiv 2609.00267Policy dependency / Stack layerPattern: four coding-agent CLIs shipped self-hosted or in-network execution controls in the same weekCursorStack layer / ContrastContext Privilege Escalation Attacks Hit 12 Real Agent Harnesses, Including Claude Code and CodexarXiv 2609.01222Stack layer / ContrastOpenClaw 2.0 Ships With 16,000 Merged PRs and Detects Your Existing ChatGPT and Claude Subscriptions Instead of Asking for API KeysInfoQ (corroborated by Dataconomy)Policy dependency / Stack layerFour advisories land on Databricks' Omnigent meta-harness, one critical, all reported by an autonomous security agentGitHub Security AdvisoriesPolicy dependency / Stack layerCo-evolving the harness alongside the policy cut AgentDojo attack success 3x while raising benign utilityarXiv 2609.02786