Vulnerability library
Security checkFebruary 19, 2026

Unauthorized npm publish of [email protected] with modified postinstall script

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Low severitynpmcline

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM registry: [email protected]. The published package contains a modified package.

Recommendation

Update the cline package to the latest compatible version. Followings are version details:

  • Affected version(s): = 2.3.0
  • Patched version(s): 2.4.0

References

Could your website be exposed too?

SmartScanner can check your website for Unauthorized npm publish of [email protected] with modified postinstall script and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated February 19, 2026