Rogue Agent Watch › Records › amazon-q-developer-extension-compromise

Amazon Q Developer VS Code extension compromise (data-wiping prompt injection)

Disclosed · added to the index · last updated

Grades

Verification status
Confirmed — Confirmed by a first-party disclosure or multiple independent credible sources.
Sourcing confidence
Primary — Backed by primary sourcing — first-party disclosure, vendor incident report, government advisory, or court documents.
AI role
Significant — AI materially enabled or accelerated the operation, but was one of several important components.
Severity
High — Significant confirmed harm to one or more organizations.

Summary

An attacker used an inappropriately scoped GitHub token to merge malicious content into the open-source repository behind the Amazon Q Developer extension for Visual Studio Code, shipping it in release 1.84.0. The injected content was a system prompt instructing the AI coding agent to wipe local files and cloud resources. AWS confirmed the compromise in security bulletin AWS-2025-015 (CVE-2025-8217), revoked the credentials, removed the code and released a fixed version; per AWS the injected code failed to execute due to a syntax error.

Impact as stated

Malicious data-wiping instructions were shipped in an official extension release, but AWS states the code was unsuccessful in executing due to a syntax error. Credentials were revoked and the code removed.

Facts as stated by sources

Actor
lkmanka58 (Single operator)
Category
Infrastructure abuse / supply chain
Models named
not named by sources
Model families
Other / unspecified
Agentic autonomy level
Not applicable
Guardrail bypass
Indirect prompt injection
Attack lifecycle phases
Initial access, Execution, Impact
Target sectors
not stated
Target countries
not stated
Organisations affected
not stated
Records exfiltrated
not stated

Framework mappings

MITRE ATLAS
AML.T0051, AML.T0081
CVE
CVE-2025-8217

Mitigations as stated

  • AWS revoked the compromised credentials, removed the code, and released a fixed extension version.

Map

No cited source states a location; this record is listed beside the map, never plotted.

Sources (2)

  1. AWS Security Bulletin AWS-2025-015
    Amazon Web Services · Vendor report · · archived copy
  2. Amazon AI coding agent hacked to inject data wiping commands
    BleepingComputer · News · · archived copy

Cite this record

Agentic Attack Index (MLSecOpsHub), dataset v0.3.0, record "amazon-q-developer-extension-compromise". https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents/amazon-q-developer-extension-compromise.json — CC BY-SA 4.0.

Record JSON · Source YAML · Report a correction