Malicious PR injected a data-wiping prompt into the Amazon Q VS Code extension
2025-amazon-q-wiper-supply-chain · 2025-07-13
A pull request from an alias contributor merged a malicious system prompt into the Amazon Q Developer VS Code extension, instructing the agent to delete local files and wipe AWS resources. The compromised version 1.84.0 shipped to a base of nearly one million installs but failed to execute due to a syntax error.
System
- Framework
- Amazon Q Developer (VS Code extension)
- Tools
- aws-cli, filesystem
- Vendor
- Amazon Web Services
- Autonomy
- supervised-autonomous
Classification
- Primary class
- supply-chain-compromise
- Chain
- supply-chain-compromise/extension → unsafe-action/data-deletion
- Attack vector
- supply-chain
- Causation
- entity: human · intentionality: intentional · timing: pre-deployment
Trigger
A contributor operating under an alias submitted a pull request to the Amazon Q VS Code extension repository. The merged code contained a malicious system prompt instructing the agent to act as a "system cleaner" and delete local files and wipe AWS cloud resources.
Root cause
A pull request from an untrusted contributor was merged into the extension codebase with insufficient review/permission controls, allowing a malicious agent-directing prompt into a widely distributed release.
Contributing factors
- System prompts were not treated as security-critical artifacts in review.
- Contribution permissions allowed an untrusted party's change to reach release.
- Releases were not signed/verified in a way that would flag the injected instruction.
Detection
Reported by security researchers after the compromised version shipped; analysed by ReversingLabs and others.
Recovery
Amazon revoked and replaced the compromised credentials, removed the malicious code, and released a new version of the tool.
Prevention
Enforce strict review and permission controls on contributions to agent-directing code; treat system prompts as security-critical artifacts; sign and verify releases; constrain what agent instructions may command.
Blast radius
- Data
- The malicious prompt targeted deletion of users' home directories and local files and destruction of AWS resources (EC2, S3, IAM). Version 1.84.0 shipped to a user base of nearly one million installs. internal
- User harm
- No customer environments were affected; AWS reported the destructive code failed to execute due to a syntax error. none-reported
- Scope
- ~1M extension installs
- Reversibility
- irreversible
References
- OWASP LLM
- LLM03 LLM06
- Tags
- supply-chain ide-extension near-miss
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2025-amazon-q-wiper-supply-chain/
@misc{2025-amazon-q-wiper-supply-chain,
title = {Malicious PR injected a data-wiping prompt into the Amazon Q VS Code extension},
year = {2025},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2025-amazon-q-wiper-supply-chain/}
}