id: PIR-2026-0030title: Outside contributor plants a natural-language wipe-your-system prompt in the aws-toolkit-vscode repo; it auto-builds into official release v1.84.0 (~1M installs) and fails only on a syntax errordate_occurred: 2025-07-13 (malicious PR/commit) -> 2025-07-17 (poisoned v1.84.0 published)date_detected: ~2025-07-23 (researchers/reporting flag the malicious commit; attacker also contacted press)date_disclosed: 2025-07-23/24 (404 Media report; AWS bulletin AWS-2025-015 and GitHub advisory GHSA-7g7f-ff96-5gcw; clean v1.85.0 shipped)status: correctedagent_description: Amazon Q Developer extension for VS Code - agentic coding assistant with shell and AWS CLI execution on the developer's host; distributed by AWS through the VS Code marketplace at ~1M installs (marketplace count ~950K+).operator_type: enterprise (AWS-built and -distributed; end operators are individual developers)autonomy_level: human-on-the-loop typical (agent executes commands with configurable confirmation); the payload targeted whatever autonomy each install allowedmodel_stack: Amazon Q Developer hosted models (payload was model-agnostic natural language)harness: VS Code extension + open-source aws-toolkit-vscode repo + AWS CodeBuild release pipeline (the compromised link)authority_scope: code execution (shell on host), credentials (local AWS credentials), data access (home directory), cloud resources (EC2/S3/IAM via AWS CLI)funds_at_risk_usd: unknown/unbounded (fleet-wide destructive potential across ~1M installs; no meaningful cap existed)blast_radius: customers/third parties (every installed developer machine + their AWS accounts)root_cause: supply-chain-compromise (primary; v0.1 taxonomy - the compromised release pipeline is the failure); contributing prompt-injection (the payload's form: a natural-language instruction to the agent) and operator-error (overscoped GitHub token in the CodeBuild configuration granting a stranger admin-equivalent access)failure_locus: dependency (marketplace-distributed tool poisoned upstream of every operator)exploitation_status: in-wild-payload-failed (malicious artifact reached ~1M real installs for ~5-6 days; payload did not execute)mechanism: An outsider submitted a PR to aws-toolkit-vscode on ~July 13 and, via an inappropriately scoped GitHub token in the CodeBuild configuration, obtained admin-level commit access ("admin credentials on a silver platter," per the attacker to 404 Media). They committed a prompt instructing the agent to "clean a system to a near-factory state" - wipe the home directory and delete EC2/S3/IAM resources via AWS CLI. The commit auto-built into official v1.84.0, published July 17. A syntax/formatting error prevented the injected prompt from executing. AWS revoked credentials, removed the code, and shipped v1.85.0.adversary_present: yes (attacker claims the payload was deliberately defanged as a demonstration - unverifiable)severity: near-miss (full distribution of a destructive payload; zero realized execution)direct_loss_usd: 0 (per AWS: no changes to any services or customer environments)indirect_loss_usd: unknown (AWS incident response; customer update burden)downtime: none (v1.84.0 pulled; users required to update to 1.85.0)data_exposure: none reporteddetected_by: third-party / attacker-disclosure (security researchers flagged the commit; the attacker simultaneously self-disclosed to 404 Media) - not by AWS pipeline controlstime_to_detect: ~6-10 days from malicious commit; ~5-6 days of poisoned release livetime_to_recover: ~1-2 days from detection (credentials revoked, build pulled, v1.85.0 released)remediation: credential revocation, malicious code removal, forced version deprecation, security bulletinstructural_fix: release-pipeline credential scoping tightened (per AWS); the deeper fact stands - a marketplace agent's prompt channel is part of its supply chaincontrols_that_worked: none - the outcome was bounded by the attacker's defective (or deliberately defanged) payload, not by any AWS or user control. Actuarially this is luck, not defense; recorded per v0.1 exploitation_status exactly to avoid conflating it with defended near-misses.telemetry_grade: operator-logs (AWS's account), corroborated by public git history and the marketplace release recordsources:independence: good - first-party bulletins plus unaffiliated security press; attacker's account via 404 Media (referenced in the above).aiid_incident_id: 1158 (https://incidentdatabase.ai/cite/1158/) - cross-reference; primaries verified independentlyconfidence: high on timeline and mechanism; medium on "zero damage" (rests on AWS's attestation plus the attacker's claim - named weakest link)supply-chain-compromise with failure_locus dependency - the v0.1 amendment names this exact cluster. Prompt-injection kept as contributing (payload form).aiid_incident_id cross-reference (AIID 1158), matched against the AIID weekly database export (2026-08-17). A cross-reference, not a re-verification; no claim changed.See also - this event in the AI Incident Database: incident 1158.