Amazon’s AI coding agent was hacked – update now to avoid possible risks, users warned




  • Experts claim Amazon Q Developer Extension for VSC v1.84.0 had some dodgy code
  • This has now been removed, with version 1.85.0 offering a clean fix
  • Around 5.6% of VSC extensions have been compromised

A hacker has planted data-wiping code into the Amazon Q Developer Extension for Visual Studio Code (VSC) – a free GenAI extension with nearly one million installs from the Microsoft VSC marketplace designed to help developers code, debug, document and configure projects.

On July 13 2025, the malicious commit from ‘lkmanka58’ on GitHub included a prompt to delete system and cloud resources, with Amazon unknowingly publishing the compromised version (1.84.0) on July 17.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *