PipeRoll - Agent Incident Registry

PIR-2026-0030

Amazon Q Developer VS Code extension ships with an injected system-wipe prompt (v1.84.0)
Cite as: PipeRoll PIR-2026-0030, Amazon Q Developer VS Code extension ships with an injected… (2025-07) - https://piperoll.org/pir/2026-0030

PIR-2026-0030 - Amazon Q Developer VS Code extension ships with an injected system-wipe prompt (v1.84.0)

The agent

Authority

The failure

Impact

Detection and recovery

Evidence

Verification notes

  1. Root cause reclassified under v0.1. Intake (drafted pre-amendment) filed this as primary prompt-injection. Under the amended taxonomy the primary is supply-chain-compromise with failure_locus dependency - the v0.1 amendment names this exact cluster. Prompt-injection kept as contributing (payload form).
  2. Bulletin conflict resolved. Intake flagged AWS-2025-015 vs AWS-2025-019. Verified: AWS-2025-015 (July 2025) is this incident; AWS-2025-019 (Oct 2025) covers unrelated Embrace The Red-reported prompt-injection/RCE issues in Q Developer and Kiro. AWS-2025-019 removed from sources.
  3. Exposure window corrected. Intake said the poisoned release was live "~2 days"; the verified timeline (v1.84.0 published 2025-07-17, detection ~2025-07-23) gives ~5-6 days of distribution.
  4. Intake's bleepingcomputer/404media/techradar/devops.com URLs not re-verified directly (404 Media's reporting reached me via secondary sources); replaced with verified equivalents (SC Media, AWSInsider, ReversingLabs).