Cline CLI 2.3.0 was published with a stolen npm token, installing OpenClaw in an 8-hour attack affecting ~4,000 downloads.
While the AI itself wasn’t weaponized, the technique raises concerns about AI agents with broad system access.
The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.
Self-hosted agents execute code with durable credentials and process untrusted input. This creates dual supply chain risk, ...
The npm registry now includes Socket security analysis links directly on package pages to help developers assess supply chain risks.
Open source has always had issues, but the benefits outweighed the costs/risks. AI is not merely exponentially accelerating ...
Trusted registries are widely treated as a key component of Software Bill of Materials (SBOM) - driven supply chain security ...
Peter Steinberger will lead personal agent development, while the viral open-source project will continue under an ...
The rice assistance policy is part of the Indonesian government’s stimulus package aimed at bolstering economic growth in the ...
European techies looking for the biggest payday are far better off in Switzerland than anywhere else, with average salaries ...
MILAN -- Italy has ramped up security ahead of the opening ceremony of the Milan Cortina Winter Olympics on Friday, with thousands of agents protecting athletes, spectators and global leaders at ...
President Trump signed a massive funding bill to end the partial government shutdown on Tuesday, bringing an end to the standoff after four days with a new fight over immigration on the horizon. The ...