STUPID-2026-0035

Hacker slipped a data-wiping prompt into Amazon Q's VS Code extension, shipped to ~1M installs

10.0critical
July 24, 2025Verified
  1. Instruction given

    Ship the Amazon Q Developer extension for VS Code to users.

  2. Expected behavior

    Vet community pull requests so no attacker can inject agent instructions into an official release.

  3. Actual behavior

    An attacker submitted a pull request to the open-source aws-toolkit-vscode repo, was granted admin access, and added a prompt instructing the agent to 'clean a system to a near-factory state,' delete filesystem and cloud resources via bash and AWS CLI, and run continuously until done. It shipped in the official v1.84.0 release.

  4. Damage

    The malicious prompt reached an extension with roughly one million installs. A syntax error prevented it from executing, and AWS says no customer environment suffered deletion; AWS revoked credentials and shipped a clean v1.85.0 within a day of disclosure. The near-miss exposed how a single commit can weaponize an AI dev tool at scale.

In July 2025 an attacker submitted a pull request to the open-source aws-toolkit-vscode GitHub repository, was granted admin credentials, and injected a prompt-injection payload that shipped in the official Amazon Q for VS Code v1.84.0 release on July 17. The prompt told the AI assistant its goal was to 'clean a system to a near-factory state,' delete filesystem and cloud resources using bash and AWS CLI commands, and 'run continuously until the task is complete.' With nearly one million installs, the compromised extension could have hit developers working on production and critical-infrastructure projects. A syntax error kept the destructive code from actually running; on July 23 researchers flagged suspicious behavior, and by the next day AWS had removed the code, revoked credentials, and released a clean v1.85.0. AWS reported no evidence of customer data loss — but the incident showed how one malicious commit can turn a trusted AI coding agent into a wiper delivered to a million machines.

Classification

Root cause
Tool Misuse
Domain
Infra

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.