How to Steal npm Publish Tokens by Opening GitHub Issues, by @neciudan.dev:

https://neciudan.dev/cline-ci-got-compromised-here-is-how

#npm #github #security #ai

How to steal npm publish tokens by opening GitHub issues

A chain of vulnerabilities and pretty clever attack strategies led to the compromise of the Cline CLI. Let me explain what happened and what you can do to protect yourself.

Neciu Dan