Amazon's AI Coding Assistant Q Compromised: Hacker Injects Data-Wiping Commands

Reviewed byNidhi Govil

7 Sources

A hacker successfully planted malicious code in Amazon's AI coding assistant Q, potentially exposing nearly 1 million users to system wiping risks. The incident raises serious questions about AI security in software development.

The Breach: A Hacker's Warning Shot

In a startling development, Amazon's AI-powered coding assistant, Q, was compromised by a hacker who successfully injected potentially destructive code into the tool. The incident, which occurred in July 2025, exposed nearly one million users of the Amazon Q Developer Extension for Visual Studio Code to potential system-wiping risks 1.

Source: ZDNet

Source: ZDNet

The hacker, using the alias 'lkmanka58', managed to submit a pull request to Amazon Q's GitHub repository, which was unexpectedly approved. The malicious commit included a prompt instructing the AI agent to "clean a system to a near-factory state and delete file-system and cloud resources" 2. This compromised version (1.84.0) was unknowingly published by Amazon on July 17, making it available to the entire user base 3.

Amazon's Response and Security Concerns

Upon discovering the breach on July 23, Amazon quickly investigated and released a clean version (1.85.0) the following day, removing the unapproved code 3. In a security bulletin, AWS stated:

"We immediately revoked and replaced the credentials, removed the unapproved code from the codebase, and subsequently released Amazon Q Developer Extension version 1.85.0 to the marketplace." 2

However, Amazon's handling of the incident has drawn criticism from security experts and developers. The company initially failed to issue a public announcement and was accused of attempting to cover up the breach by quietly removing the compromised version without proper disclosure 1.

Implications for AI in Software Development

Source: Bleeping Computer

Source: Bleeping Computer

This incident has raised serious questions about the integration of AI tools into software development pipelines. Corey Quinn, chief cloud economist at The Duckbill Group, commented, "This isn't 'move fast and break things,' it's 'move fast and let strangers write your roadmap.'" 4

The breach exposed critical flaws in how AI tools are managed and secured. It highlighted the need for robust code review processes and proper repository management practices. As Steven Vaughan-Nichols of ZDNet pointed out, the issue was not with open source itself, but rather with how Amazon implemented its open-source workflows 1.

The Hacker's Motivation

Interestingly, the hacker claimed that their actions were intended as a warning rather than a malicious attack. In comments to 404 Media, they described Amazon's AI security measures as "security theater" and stated that the wiper was designed to be defective 2. Their goal was reportedly to expose Amazon's inadequate safeguards and prompt improvements in security practices.

Broader Implications and User Advice

Source: The Register

Source: The Register

This incident serves as a wake-up call for the tech industry regarding the risks associated with AI integration in development workflows. It underscores the importance of vigilance and thorough security measures when incorporating AI tools into software development processes 4.

Users of the Amazon Q Developer Extension are strongly advised to update to version 1.85.0 or later to mitigate any potential risks 5. Furthermore, developers are cautioned not to unconditionally trust IDE extensions and AI assistants, highlighting the need for ongoing vigilance in the rapidly evolving landscape of AI-assisted software development.

Explore today's top stories

Google Unveils Gemini 2.5 Deep Think: A Powerful AI Model for Complex Problem-Solving

Google releases Gemini 2.5 Deep Think, an advanced AI model designed for complex queries, available exclusively to AI Ultra subscribers at $250 per month. The model showcases improved performance in various benchmarks and introduces parallel thinking capabilities.

Ars Technica logoTechCrunch logoCNET logo

17 Sources

Technology

14 hrs ago

Google Unveils Gemini 2.5 Deep Think: A Powerful AI Model

OpenAI Secures $8.3 Billion in Funding, Reaching $300 Billion Valuation

OpenAI raises $8.3 billion in a new funding round, valuing the company at $300 billion. The AI giant's rapid growth and ambitious plans attract major investors, signaling a significant shift in the AI industry landscape.

TechCrunch logoCNBC logoThe New York Times logo

10 Sources

Business and Economy

7 hrs ago

OpenAI Secures $8.3 Billion in Funding, Reaching $300

Reddit's AI-Driven Strategy Boosts Revenue and User Engagement

Reddit's Q2 earnings reveal significant growth driven by AI-powered advertising tools and data licensing deals, showcasing the platform's successful integration of AI technology.

TechCrunch logoReuters logoDataconomy logo

7 Sources

Business and Economy

15 hrs ago

Reddit's AI-Driven Strategy Boosts Revenue and User

Reddit Aims to Become a Go-To Search Engine with Unified AI-Powered Search Experience

Reddit is repositioning itself as a search engine, integrating its traditional search with AI-powered Reddit Answers to create a unified search experience. The move comes as the platform sees increased user reliance on its vast community-generated content for information.

TechCrunch logoCNET logoThe Verge logo

9 Sources

Technology

23 hrs ago

Reddit Aims to Become a Go-To Search Engine with Unified

GPT-5: OpenAI's Game-Changing AI Model Set for Imminent Release

OpenAI is poised to launch GPT-5, a revolutionary AI model that promises to unify various AI capabilities and automate model selection for optimal performance.

ZDNet logoEconomic Times logo

2 Sources

Technology

15 hrs ago

GPT-5: OpenAI's Game-Changing AI Model Set for Imminent
TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo