Security researcher Adnan Khan disclosed ‘Clinejection,’ a multi-stage attack chain in which a single malicious GitHub issue title tricked Cline’s Claude-powered AI issue-triage bot into running commands with elevated repository permissions. On 17 February 2026, an attacker used credentials obtained through this chain to publish a tampered version of the Cline CLI package to npm, which covertly installed an unauthorized third-party AI agent via a postinstall script. Approximately 4,000 developer and CI/CD machines downloaded the compromised package before it was pulled roughly eight hours later.