Skip to main content
VerifiedInjection

Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine

Version 1.84.0 of the Amazon Q Developer extension for Visual Studio Code was published carrying attacker supplied code. AWS states the malicious code was distributed but failed to execute because of a syntax error. The GitHub advisory attributes the entry point to an improperly scoped build token. The injected text told an agent with filesystem and shell tools to clean the system to a near factory state.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0005
Kind
Injection
Jurisdiction
United States
Last verified
Added
  • AWS security bulletin AWS-2025-015 states the malicious code was distributed with the extension but was unsuccessful in executing due to a syntax error.
  • GitHub advisory GHSA-7g7f-ff96-5gcw carries CVE-2025-8217 and names an improperly scoped GitHub token in the build configuration as the entry point.
  • Version 1.84.0 was removed from distribution and version 1.85.0 was published as the fix.
  • 404 Media published the injected prompt, which instructs an AI agent with filesystem and shell access to clean a system to a near factory state and delete cloud resources.
  • AWS states no customer environments or services were changed.

Dimension by dimension

7 dimensions, each one stated, silent or open

Identity, Authorization, Human approval, Limits, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
An outside contributor obtained write access to the vendor's own release repository.GitHub security advisory GHSA-7g7f-ff96-5gcw, primary source, 26 July 2025.
AuthorizationSilent
The advisory names an improperly scoped build token as the cause, so the build credential could do more than build.GitHub security advisory GHSA-7g7f-ff96-5gcw, primary source, 26 July 2025.
Human approvalSilent
The change reached a signed release without a review that caught it.GitHub security advisory GHSA-7g7f-ff96-5gcw, primary source, 26 July 2025.
LimitsSilent
Nothing bounded the payload; it did not run only because it was malformed, which is luck rather than a control.AWS security bulletin AWS-2025-015, primary source, 23 July 2025.
Logging and auditStated
AWS inspected the shipped artifact and established exactly what was distributed and that it did not execute.AWS security bulletin AWS-2025-015, primary source, 23 July 2025.
RevocationStated
The affected version was pulled from distribution and a fixed version shipped.AWS security bulletin AWS-2025-015, primary source, 23 July 2025.
AccountabilityStated
AWS published a numbered bulletin and a CVE bearing advisory naming the root cause.GitHub security advisory GHSA-7g7f-ff96-5gcw, primary source, 26 July 2025.

What it changes

For a team deploying an agent

This is the supply chain shape of the agent problem: the instruction reached the agent before the user did. The control that failed is authorization on the build system, not on the agent. Scope release tokens to the one repository and one action they need, require review on anything that lands in a shipped agent's instructions, and pin the extension versions your developers run so a bad release cannot arrive silently.

Sources

What this record was verified against

  1. AWS security bulletin AWS-2025-015Primary · 23 July 2025
  2. GitHub security advisory GHSA-7g7f-ff96-5gcwPrimary · 26 July 2025
  3. 404 Media, Hacker plants computer wiping commands in Amazon's AI coding agentSecondary · 23 July 2025

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0005 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), amazon q developer for vs code shipped carrying an injected prompt to wipe the machine.
APA
GAGE (Global Academy of Generative-AI Education). (2026). Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0005-amazon-q-developer-extension-shipped-wiper-prompt
MLA
"Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0005-amazon-q-developer-extension-shipped-wiper-prompt.
Chicago
GAGE (Global Academy of Generative-AI Education). "Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0005-amazon-q-developer-extension-shipped-wiper-prompt.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0005-amazon-q-developer-extension-shipped-wiper-prompt

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for United States and every injection record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.