Microsoft Defender was able to confirm a small but noticeable uptick in installations of OpenClaw initiated by Cline CLI installation script during the supply chain compromise of their NPM package that lasted approximately eight hours on February 17, 2026 between 11:26 and 19:30… pic.twitter.com/27IeNQd4jF
— Microsoft Threat Intelligence (@MsftSecIntel) February 19, 2026