jqwik library contained hidden prompt injection telling AI coding agents to delete app output
A developer added an undisclosed instruction to the jqwik library that directed AI coding agents processing the code to delete application output, reportedly out of frustration with 'vibe coders'. The hidden prompt injection was reported publicly in late May 2026.
Disclosed 29 May 2026 · Record updated 13 September 2026
Impact
AI coding agents reading the library's code could be instructed to delete application output data.
Our coverage
No articles linked to this incident yet.
Sources
- arstechnica.comhttps://arstechnica.com/security/2026/05/fed-up-with-vibe-coders-dev-sneaks-data-nuking-prompt-injection-into-their-code
