Sev0AI security incidents, tracked

All incidents / Supply chain and access

Wiper prompt slipped into Amazon Q's official VS Code extension

Amazon Web Services, disclosed 23 Jul 2025. Supply chain and access Data destroyed Low

An attacker used an over-scoped GitHub token in AWS's build pipeline to insert a prompt telling the Amazon Q coding assistant to wipe local files and cloud resources. The tampered version shipped to users of an extension with nearly a million installs, but a syntax error stopped it from running. AWS pulled it and released a fix.

Disclosed
23 Jul 2025
Organization
Amazon Web Services
Vendor
Amazon
Product
Amazon Q Developer
Kind of AI
Coding agent
AI's role
Poisoned supply chain
How it happened
Supply chain and access: Poisoned package
Harm
Data destroyed
Data involved
Unknown
Reach
No known access
Severity
Low
Model at fault
No
Status
Confirmed
Vulnerability IDs
CVE-2025-8217

Sources

  1. https://github.com/aws/aws-toolkit-vscode/security/advisories/GHSA-7g7f-ff96-5gcw
  2. https://www.scworld.com/news/amazon-q-extension-for-vs-code-reportedly-injected-with-wiper-prompt

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Wiper prompt slipped into Amazon Q's official VS Code extension", https://sev0.fyi/incidents/2025-07-23-amazon-q-wiper-prompt/