STUPID-2026-0035
Hacker slipped a data-wiping prompt into Amazon Q's VS Code extension, shipped to ~1M installs
Instruction given
Ship the Amazon Q Developer extension for VS Code to users.
Expected behavior
Vet community pull requests so no attacker can inject agent instructions into an official release.
Actual behavior
An attacker submitted a pull request to the open-source aws-toolkit-vscode repo, was granted admin access, and added a prompt instructing the agent to 'clean a system to a near-factory state,' delete filesystem and cloud resources via bash and AWS CLI, and run continuously until done. It shipped in the official v1.84.0 release.
Damage
The malicious prompt reached an extension with roughly one million installs. A syntax error prevented it from executing, and AWS says no customer environment suffered deletion; AWS revoked credentials and shipped a clean v1.85.0 within a day of disclosure. The near-miss exposed how a single commit can weaponize an AI dev tool at scale.
Classification
- Agent
- Amazon Q
- Failure mode
- Security Vulnerability
- Root cause
- Tool Misuse
- Domain
- Infra
- Source
- News Report
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.