Wiper prompt slipped into Amazon Q's official VS Code extension
An attacker used an over-scoped GitHub token in AWS's build pipeline to insert a prompt telling the Amazon Q coding assistant to wipe local files and cloud resources. The tampered version shipped to users of an extension with nearly a million installs, but a syntax error stopped it from running. AWS pulled it and released a fix.
- Disclosed
- 23 Jul 2025
- Organization
- Amazon Web Services
- Vendor
- Amazon
- Product
- Amazon Q Developer
- Kind of AI
- Coding agent
- AI's role
- Poisoned supply chain
- How it happened
- Supply chain and access: Poisoned package
- Harm
- Data destroyed
- Data involved
- Unknown
- Reach
- No known access
- Severity
- Low
- Model at fault
- No
- Status
- Confirmed
- Vulnerability IDs
- CVE-2025-8217