Rogue Agent Watch › Records › amazon-q-developer-extension-compromise
Amazon Q Developer VS Code extension compromise (data-wiping prompt injection)
Disclosed · added to the index · last updated
Grades
- Verification status
- Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
- Sourcing confidence
- Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
- AI role
- Significant — AI materially enabled or accelerated the operation, but was one of several important components.
- Severity
- High — Significant confirmed harm to one or more organizations.
Summary
An attacker used an inappropriately scoped GitHub token to merge malicious content into the open-source repository behind the Amazon Q Developer extension for Visual Studio Code, shipping it in release 1.84.0. The injected content was a system prompt instructing the AI coding agent to wipe local files and cloud resources. AWS confirmed the compromise in security bulletin AWS-2025-015 (CVE-2025-8217), revoked the credentials, removed the code and released a fixed version; per AWS the injected code failed to execute due to a syntax error.
Impact as stated
Malicious data-wiping instructions were shipped in an official extension release, but AWS states the code was unsuccessful in executing due to a syntax error. Credentials were revoked and the code removed.
Facts as stated by sources
- Actor
- lkmanka58 (Single operator)
- Category
- Infrastructure abuse / supply chain
- Models named
- not named by sources
- Model families
- Other / unspecified
- Agentic autonomy level
- Not applicable
- Guardrail bypass
- Indirect prompt injection
- Attack lifecycle phases
- Initial access, Execution, Impact
- Target sectors
- not stated
- Target countries
- not stated
- Organisations affected
- not stated
- Records exfiltrated
- not stated
Framework mappings
- MITRE ATLAS
- AML.T0051, AML.T0081
- CVE
- CVE-2025-8217
Mitigations as stated
- AWS revoked the compromised credentials, removed the code, and released a fixed extension version.
Map
No cited source states a location; this record is listed beside the map, never plotted.
Sources (2)
- AWS Security Bulletin AWS-2025-015
Amazon Web Services · Vendor report · · archived copy - Amazon AI coding agent hacked to inject data wiping commands
BleepingComputer · News · · archived copy
Cite this record
Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "amazon-q-developer-extension-compromise". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/amazon-q-developer-extension-compromise.json — CC BY-SA 4.0.