AWS
Disclosed Jul 23, 20251 year agoUnverified
Hacker slipped data-wiping prompt into Amazon Q coding assistant extension
A hacker got a commit into the Amazon Q Developer extension for VS Code via its GitHub repository that injected a prompt telling the AI agent to wipe local files and cloud resources; AWS shipped the tainted version 1.84.0 to users, then revoked credentials and released a clean 1.85.0.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jul 23, 2025 |
| Attack | Supply chain |
| Data exposed | Source code, Credentials and tokens |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Amazon AI coding agent hacked to inject data wiping commandsbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jul 23, 2025 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.