The malicious version of Cline's npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed.
Researchers say an AI-powered code scanner traced untrusted data across layers of OpenClaw, exposing exploitable weaknesses including SSRF, authentication bypass, and path traversal.