A detailed breakdown of 'Clinejection', a five-step supply chain attack that compromised ~4,000 developer machines in February 2026. An attacker injected a malicious instruction into a GitHub issue title, which an AI triage bot (using claude-code-action) executed as a legitimate command. This triggered cache poisoning via

Sort: