How to Steal npm Publish Tokens by Opening GitHub Issues, by @neciudan.dev:
https://neciudan.dev/cline-ci-got-compromised-here-is-how
#npm #github #security #ai
A chain of vulnerabilities and pretty clever attack strategies led to the compromise of the Cline CLI. Let me explain what happened and what you can do to protect yourself.