How Cline Was Compromised: Prompt Injection and Dangling Commits in the Cline Supply Chain Attack
A deep dive into the Cline compromise: how an attacker used a GitHub dangling commit, a typosquatted account, and prompt injection against an AI triage agent to achieve remote code execution on Cline's GitHub Actions CI/CD runners.