The July 2025 pull request to the aws-toolkit-vscode repository introduced a malicious prompt that instructed the AI coding agent in the Q Developer extension to wipe local and cloud resources. Amazon’s security team removed the code, revoked the over‑privileged GitHub token, and shipped a new build that requires explicit human confirmation before the agent can execute any command that would affect the system.
What Changed in the Q Developer Release
Four days after the pull request was merged, the extension was distributed to nearly a million VS Code users. The malicious change added a build‑time download and a prompt that bypassed the agent’s normal approval flow via special flag values. The prompt failed to run because of a formatting error, but the underlying risk was real. After the incident, Amazon:
- Removed the malicious code from the repository.
- Revoked the GitHub access token that had broader permissions than required for the build service.
- Issued a clean release within two days.
- Updated both Q Developer and the later Kiro agent to enforce a human‑in‑the‑loop confirmation for any command that would modify the file system or cloud resources.
Why the Change Matters to Engineers
AI coding agents are no longer passive assistants; they can invoke shell commands (find, etc.) and interact with cloud APIs. When an attacker can inject a prompt into the agent’s supply chain, the agent will obey without the hesitation a human would have. This blurs the line between a software bug and a supply‑chain compromise, making it essential for AI engineers, platform engineers, DevOps/SRE staff, and security teams to treat the agent’s execution path as an attack surface.
Architectural and Operational Implications
Several concrete considerations arise from the incident:
- Token Scope Management: The compromised GitHub token had more permissions than the build job required. Limiting token scopes to the minimum necessary reduces the blast radius of a credential leak.
- Build‑pipeline Integrity: The build service automatically packaged code from the repository without additional validation. Introducing a step that verifies the integrity of packaged assets (e.g., reproducible builds, signed artifacts) can catch unauthorized modifications before release.
- Command Gating for AI Agents: Requiring explicit human confirmation for destructive actions forces a manual review point, preventing a malicious prompt from executing silently.
- Monitoring for Prompt Injection: Since the agent can accept prompts at runtime, logging and alerting on unusual command patterns (e.g., mass delete, cloud‑resource termination) can provide early detection of an injection attempt.
- Supply‑chain Visibility: The incident demonstrates that a single pull request can affect a million downstream installations. Maintaining an audit trail of changes that affect agent behavior is critical for rapid response.
Related CloudNinjas coverage: DevOps.
What This Means For Practitioners
Teams that incorporate AI coding agents should immediately audit the permissions of any service accounts used in CI/CD pipelines and tighten them to the least‑privilege set. Enable or enforce human confirmation for any agent‑initiated command that alters files, deletes resources, or invokes cloud APIs. Add integrity checks to the build and release process to detect unexpected script modifications. Finally, instrument the agent runtime to log command intent and set up alerts for patterns that resemble mass‑deletion or credential‑escalation attempts. These steps turn a reactive response into a proactive defense against similar supply‑chain attacks.
