logo

Amazon AI coding agent hacked to inject data wiping commands

ID: a1d2173f-7a81-50b5-91cd-40df62463dfb

STIX ID: report--a1d2173f-7a81-50b5-91cd-40df62463dfb

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2025-07-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Amazon Q VS Code extension compromised via malicious commit** — A contributor account submitted an unapproved commit that introduced a data-wiping prompt into the Amazon Q Developer Extension (v1.84.0) published to the VS Code marketplace; AWS removed the code, revoked credentials, and released v1.85.0 after security reports, with AWS stating no customer resources were impacted though some researchers indicate the code may have executed without causing harm.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.