Skip to content

AWS

Disclosed Jul 23, 20251 year agoUnverified

Hacker slipped data-wiping prompt into Amazon Q coding assistant extension

A hacker got a commit into the Amazon Q Developer extension for VS Code via its GitHub repository that injected a prompt telling the AI agent to wipe local files and cloud resources; AWS shipped the tainted version 1.84.0 to users, then revoked credentials and released a clean 1.85.0.

What is known

People affectedNot stated in the sources we have
DisclosedJul 23, 2025
AttackSupply chain
Data exposedSource code, Credentials and tokens
SectorTech · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Source
Amazon AI coding agent hacked to inject data wiping commandsbleepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalJul 23, 2025
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about AWS

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.