Compromised Amazon Q extension told AI to delete everything – and it shipped
ID: 6c89b87f-d266-5e4e-b80a-b0b13b1ced3b
STIX ID: report--6c89b87f-d266-5e4e-b80a-b0b13b1ced3b
Feed Name: The Register (Security)
Threat Score
A malicious commit was merged into the official Amazon Q VS Code extension (released in version 1.84) that caused the extension to download a script containing an AI prompt to delete local files and enumerate and remove AWS resources via the AWS CLI; the compromised package was available on the marketplace for two days before being reverted in 1.85, and AWS issued a security bulletin while questions remain about how the unauthorized code was merged.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
