Amazon AWS Supply-Chain Compromise
A hacker injected destructive system commands into Amazon's Visual Studio Code extension for Amazon Q via a compromised GitHub repository, distributing it through an official update. This supply chain attack exploited a lack of stringent vetting to leverage prompt injection, aiming to redefine the AI agent's behavior at runtime to erase user data and cloud resources.
What Happened
A hacker injected destructive system commands into Amazon's Visual Studio Code extension for Amazon Q via a compromised GitHub repository, distributing it through an official update. This supply chain attack exploited a lack of stringent vetting to leverage prompt injection, aiming to redefine the AI agent's behavior at runtime to erase user data and cloud resources.
Why This Matters
The evidence matters to defenders using Amazon AWS because it may place downstream environments at risk through compromised dependencies.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Confirm whether Amazon AWS is present in your environment and review the affected configuration.
Exposure
Exposure unknown
Jul 24, 2025 05:30
Exposure reason: This incident does not currently match a technology in My AI Stack.
Exploitation status: UNKNOWN
Primary entities:
Timeline
-
Incident first seen
Jul 24, 2025 05:30BugSkan first recorded this incident.
-
Hacker inserts destructive code in Amazon Q tool as update goes live - csoonline.com
Jul 24, 2025 05:30csoonline.com · Research
Sources
csoonline.com · Jul 24, 2025 05:30
A hacker injected destructive system commands into Amazon's Visual Studio Code extension for Amazon Q via a compromised GitHub repository, distributing it through an official update. This supply chain attack exploited a lack of stringent vetting to leverage prompt injection, aiming to redefine the AI agent's behavior at runtime to erase user data and cloud resources.
Open publisher sourceMy AI Stack Match
Create an account to see which incidents overlap with your AI stack.