Cline CLI 2.3.0 was published with a stolen npm token, installing OpenClaw in an 8-hour attack affecting ~4,000 downloads.
Self-hosted agents execute code with durable credentials and process untrusted input. This creates dual supply chain risk, ...