Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine
Version 1.84.0 of the Amazon Q Developer extension for Visual Studio Code was published carrying attacker supplied code. AWS states the malicious code was distributed but failed to execute because of a syntax error. The GitHub advisory attributes the entry point to an improperly scoped build token. The injected text told an agent with filesystem and shell tools to clean the system to a near factory state.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0005
- Kind
- Injection
- Jurisdiction
- United States
- Last verified
- Added
- AWS security bulletin AWS-2025-015 states the malicious code was distributed with the extension but was unsuccessful in executing due to a syntax error.
- GitHub advisory GHSA-7g7f-ff96-5gcw carries CVE-2025-8217 and names an improperly scoped GitHub token in the build configuration as the entry point.
- Version 1.84.0 was removed from distribution and version 1.85.0 was published as the fix.
- 404 Media published the injected prompt, which instructs an AI agent with filesystem and shell access to clean a system to a near factory state and delete cloud resources.
- AWS states no customer environments or services were changed.
Dimension by dimension
7 dimensions, each one stated, silent or open
Identity, Authorization, Human approval, Limits, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- An outside contributor obtained write access to the vendor's own release repository.GitHub security advisory GHSA-7g7f-ff96-5gcw, primary source, 26 July 2025.
- AuthorizationSilent
- The advisory names an improperly scoped build token as the cause, so the build credential could do more than build.GitHub security advisory GHSA-7g7f-ff96-5gcw, primary source, 26 July 2025.
- Human approvalSilent
- The change reached a signed release without a review that caught it.GitHub security advisory GHSA-7g7f-ff96-5gcw, primary source, 26 July 2025.
- LimitsSilent
- Nothing bounded the payload; it did not run only because it was malformed, which is luck rather than a control.AWS security bulletin AWS-2025-015, primary source, 23 July 2025.
- Logging and auditStated
- AWS inspected the shipped artifact and established exactly what was distributed and that it did not execute.AWS security bulletin AWS-2025-015, primary source, 23 July 2025.
- RevocationStated
- The affected version was pulled from distribution and a fixed version shipped.AWS security bulletin AWS-2025-015, primary source, 23 July 2025.
- AccountabilityStated
- AWS published a numbered bulletin and a CVE bearing advisory naming the root cause.GitHub security advisory GHSA-7g7f-ff96-5gcw, primary source, 26 July 2025.
What it changes
For a team deploying an agent
This is the supply chain shape of the agent problem: the instruction reached the agent before the user did. The control that failed is authorization on the build system, not on the agent. Scope release tokens to the one repository and one action they need, require review on anything that lands in a shipped agent's instructions, and pin the extension versions your developers run so a bad release cannot arrive silently.
Sources
What this record was verified against
- AWS security bulletin AWS-2025-015Primary · 23 July 2025
- GitHub security advisory GHSA-7g7f-ff96-5gcwPrimary · 26 July 2025
- 404 Media, Hacker plants computer wiping commands in Amazon's AI coding agentSecondary · 23 July 2025
Related
Records that sit beside this one
Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets
Global · verified 15 September 2026
The Nx postmortem states that on 26 August 2025 malicious versions of several Nx packages were published to npm.
A cloned MCP server silently copied every email agents sent through it
Global · verified 15 September 2026
The Register reports that a backdoored version added a blind copy of every message to an attacker controlled address.
A support agent invented a policy its company did not have, and customers cancelled over it
United States · verified 15 September 2026
A company representative stated publicly that there is no such policy and that users are free to use the product on multiple machines.
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing
United States · verified 15 September 2026
The vendor's own account states that the out of office reply never gets written and the agent resigns on behalf of the user instead.
A browser agent read the local file system and shipped it out while still answering the user normally
United States · verified 15 September 2026
The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely
United States · verified 15 September 2026
The Register reports that the attacker hides the commands in plain English in the issue body and the agent then posts the data as a public comment.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0005 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), amazon q developer for vs code shipped carrying an injected prompt to wipe the machine.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0005-amazon-q-developer-extension-shipped-wiper-prompt
- MLA
- "Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0005-amazon-q-developer-extension-shipped-wiper-prompt.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Amazon Q Developer for VS Code shipped carrying an injected prompt to wipe the machine." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0005-amazon-q-developer-extension-shipped-wiper-prompt.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0005-amazon-q-developer-extension-shipped-wiper-prompt
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for United States and every injection record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.