Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

Malicious prompt planted in Amazon Q Developer VS Code extension

An attacker got a pull request merged into the open-source Amazon Q Developer extension that added a prompt instructing the agent to wipe the user's machine and cloud resources. The tainted build shipped to the VS Code marketplace.

Occurred 13 July 2025 · Disclosed 23 July 2025 · Record updated 13 September 2026

Impact

Version 1.84.0 contained the destructive instruction; AWS said the code was malformed and did not execute, pulled the version and issued 1.85.0.

Our coverage

Sources

  1. 404media.cohttps://www.404media.co/hacker-plants-computer-wiping-commands-in-amazons-ai-coding-agent/
  2. aws.amazon.comhttps://aws.amazon.com/security/security-bulletins/AWS-2025-015/