agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: confirmed status: factual

Malicious PR injected a data-wiping prompt into the Amazon Q VS Code extension

2025-amazon-q-wiper-supply-chain · 2025-07-13

A pull request from an alias contributor merged a malicious system prompt into the Amazon Q Developer VS Code extension, instructing the agent to delete local files and wipe AWS resources. The compromised version 1.84.0 shipped to a base of nearly one million installs but failed to execute due to a syntax error.

System

Framework
Amazon Q Developer (VS Code extension)
Tools
aws-cli, filesystem
Vendor
Amazon Web Services
Autonomy
supervised-autonomous

Classification

Primary class
supply-chain-compromise
Chain
supply-chain-compromise/extension → unsafe-action/data-deletion
Attack vector
supply-chain
Causation
entity: human · intentionality: intentional · timing: pre-deployment

Trigger

A contributor operating under an alias submitted a pull request to the Amazon Q VS Code extension repository. The merged code contained a malicious system prompt instructing the agent to act as a "system cleaner" and delete local files and wipe AWS cloud resources.

Root cause

A pull request from an untrusted contributor was merged into the extension codebase with insufficient review/permission controls, allowing a malicious agent-directing prompt into a widely distributed release.

Contributing factors

  • System prompts were not treated as security-critical artifacts in review.
  • Contribution permissions allowed an untrusted party's change to reach release.
  • Releases were not signed/verified in a way that would flag the injected instruction.

Detection

Reported by security researchers after the compromised version shipped; analysed by ReversingLabs and others.

Recovery

Amazon revoked and replaced the compromised credentials, removed the malicious code, and released a new version of the tool.

Prevention

Enforce strict review and permission controls on contributions to agent-directing code; treat system prompts as security-critical artifacts; sign and verify releases; constrain what agent instructions may command.

Blast radius

Data
The malicious prompt targeted deletion of users' home directories and local files and destruction of AWS resources (EC2, S3, IAM). Version 1.84.0 shipped to a user base of nearly one million installs. internal
User harm
No customer environments were affected; AWS reported the destructive code failed to execute due to a syntax error. none-reported
Scope
~1M extension installs
Reversibility
irreversible

References

OWASP LLM
LLM03 LLM06
Tags
supply-chain ide-extension near-miss

Sources

Cite this incident

@misc{2025-amazon-q-wiper-supply-chain,
  title = {Malicious PR injected a data-wiping prompt into the Amazon Q VS Code extension},
  year = {2025},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2025-amazon-q-wiper-supply-chain/}
}