Cline 因 issue 标题提示注入被投毒,NPM 发布包遭污染
Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager
AI 导读
Adnan Khan 披露了一条针对 Cline GitHub 仓库的攻击链:Cline 用 anthropics/claude-code-action@v1 做 AI issue 自动分诊,配置了 Bash、Read、Write 等工具权限,且提示词包含 issue 标题,攻击者可在标题中诱导 Claude 执行任意命令,例如通过 npm install 安装指定 GitHub 包,再由其 package.json 的 preinstall 脚本运行代码。
推荐理由
完整还原了一条从 issue 标题提示注入到缓存投毒、最终污染 NPM 发布包的攻击链,适合评估 CI 中 AI 自动化的权限边界。