Hacker NewsClinejection Supply Chain Attack 4000 Developer Machines via Prompt InjectionGrith AI·high signalXBlueskyLinkedInCopy linkGitHub issue title prompt injection exploited Cline AI triage bot, poisoned npm cache, published malicious [redacted] to 4000 devsSourceSource pageGrith AI↳ Follow the threadShared entity / Stack layerSemVerBench: frontier models fail version-constraint rules like Cargo's >1.2 meaning >=1.3.0, and delegating to a resolver fixes itarXiv 2609.11180Stack layer / Threat patternCapScope stops prompt injection by giving each coding subagent typed capabilities stored outside its contextarXivStack layer / Threat patternCline Desktop 0.0.25 lets Claude Code and Codex CLI providers start sessions with no API key, and caps Codex models at real backend budgetsGitHub ReleasesStack layer / Threat patternmesh-llm v0.76.0 makes the KV prefix cache survive eviction, restarts and cold nodesGitHubStack layer / Threat patternSebastian Raschka says delete or regenerate your AGENTS.md and SKILL.md files, because the hand-holding now constrains newer modelsAhead of AI (Sebastian Raschka)Stack layer / Threat patternCline Desktop 0.0.26 shows the current branch's PR number, merge status and CI checks in the composerGitHubStack layer / Threat patternSpotify shipped a Claude Code plugin claiming 90% token savings, and r/ClaudeAI concluded it reinvented subagentsr/ClaudeAI (Spotify Engineering blog, 2026-09-03)Stack layer / Threat patternA spec-first agent framework taxonomy: persuasion, front-loaded structure, or controls the agent cannot editarXiv 2609.09671