While the Windows maker did not attribute the activity to a specific threat actor, the use of VS Code tasks and Vercel ...
Cline CLI 2.3.0 was published with a stolen npm token, installing OpenClaw in an 8-hour attack affecting ~4,000 downloads.