The Amazon Q Developer for VS Code Supply Chain Attack
Updated 5 Oct 2026 · Incident date 17 Jul 2025 · IDE extension
Amazon Q Developer for VS Code 1.83.x -> 1.84.0 (fixed in 1.85.0)extensionNode.tsAmazon Q Developer for Visual Studio Code version 1.84.0 contained malicious code that an attacker added to the extension's repository. AWS fixed the problem in version 1.85.0 and removed 1.84.0 from its distribution channels.
The injected text told the extension's AI assistant to wipe the local machine and cloud resources. AWS states that the code did not run because of a syntax error. This page lists the facts from the AWS bulletin, the GitHub advisory and press reports.
What happened
An attacker used an overly broad GitHub token in the extension's CodeBuild configuration to put malicious code into the repository. The code then went into the 1.84.0 release automatically. AWS bulletin AWS-2025-015 describes this root cause.
BleepingComputer reports this timeline:
- 13 July 2025: the attacker plants the malicious code through a pull request from a random account.
- 17 July 2025: Amazon publishes version 1.84.0 with the code inside.
- 23 July 2025: security researchers report the problem to Amazon.
- 24 July 2025: AWS releases version 1.85.0.
- 25 July 2025: the story becomes public.
The extension had nearly one million installs on the VS Code marketplace at the time, according to the same report.
The injected text told the AI assistant that its goal was to clear a system to a near-factory state and to delete file-system and cloud resources. The payload was mostly a prompt string that the extension passes to its agent through a shell call. It was not a classic binary implant.
AWS states that the code was unsuccessful in executing because of a syntax error and that no customer resources were affected. BleepingComputer notes that some security observers disagreed and said the code ran without causing harm. The sources do not settle this point.
Affected versions
- Affected: Amazon Q Developer for VS Code 1.84.0.
- Fixed: 1.85.0, released 24 July 2025.
- Last clean line before the attack: 1.83.x.
The GitHub advisory GHSA-7g7f-ff96-5gcw tracks the issue as CVE-2025-8217 with a CVSS v3.1 score of 4.0 (Moderate). The score is low because the code did not execute.
Indicators of compromise
- Extension version 1.84.0 installed in VS Code.
- SHA256 of the 1.84.0 package, as published by AWS:
47f7840ecab6312d2733e1274c513050405886c70f2037fb2f1e9099872b0464 - Prompt text in the extension code that tells an assistant to "clear a system to a near-factory state" and delete file-system and cloud resources.
The AWS bulletin lists no network indicators or domains.
How to check
List your installed extensions with versions and look for Amazon Q. Version 1.84.0 is the bad one.
code --list-extensions --show-versions | grep -i amazon
If you keep the downloaded VSIX file, compare its hash with the AWS value above.
shasum -a 256 path/to/extension.vsix
What to do now
- Open the Extensions panel in VS Code and find Amazon Q Developer.
- Click Update to install version 1.85.0 or later.
- Check that the installed version is not 1.84.0.
- If 1.84.0 was installed, review the machine for unexpected file deletions and for unexpected activity in your cloud accounts.
- Pin extension versions in managed environments and review extension updates before you roll them out.
Vigilance compares the version you trust with a new one and reports files that gain new capabilities. In this case the change sits mostly in a prompt string, so a capability diff will not always flag it. This is a known limit for this attack shape.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 23 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE extensionNode.ts It reads saved passwords and access keys and runs other programs.
Frequently asked questions
Which version of Amazon Q Developer for VS Code was malicious?
Version 1.84.0. AWS released version 1.85.0 on 24 July 2025 and removed 1.84.0 from its distribution channels.
Did the Amazon Q malicious code run?
AWS states that the code was unsuccessful in executing because of a syntax error and that no customer resources were affected. Some security observers disagreed, according to BleepingComputer.
How did the attacker get the code into Amazon Q?
AWS says an overly broad GitHub token in the extension's CodeBuild configuration let the attacker inject code into the repository. The code went into the 1.84.0 release automatically.
Sources
More supply chain attacks
- Nx Console VS Code extension 18.95.0 compromise (TeamPCP / GitHub breach) 18 May 2026
- GlassWorm self-propagating worm on Open VSX / VS Code Marketplace 17 Oct 2025
- ETHcode VS Code extension malicious pull request 17 Jun 2025
All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.