The Amazon Q Developer for VS Code Supply Chain Attack

Updated 5 Oct 2026 · Incident date 17 Jul 2025 · IDE extension

PackageAmazon Q Developer for VS Code 1.83.x -> 1.84.0 (fixed in 1.85.0)
FileextensionNode.ts

Amazon Q Developer for Visual Studio Code version 1.84.0 contained malicious code that an attacker added to the extension's repository. AWS fixed the problem in version 1.85.0 and removed 1.84.0 from its distribution channels.

The injected text told the extension's AI assistant to wipe the local machine and cloud resources. AWS states that the code did not run because of a syntax error. This page lists the facts from the AWS bulletin, the GitHub advisory and press reports.

What happened

An attacker used an overly broad GitHub token in the extension's CodeBuild configuration to put malicious code into the repository. The code then went into the 1.84.0 release automatically. AWS bulletin AWS-2025-015 describes this root cause.

BleepingComputer reports this timeline:

The extension had nearly one million installs on the VS Code marketplace at the time, according to the same report.

The injected text told the AI assistant that its goal was to clear a system to a near-factory state and to delete file-system and cloud resources. The payload was mostly a prompt string that the extension passes to its agent through a shell call. It was not a classic binary implant.

AWS states that the code was unsuccessful in executing because of a syntax error and that no customer resources were affected. BleepingComputer notes that some security observers disagreed and said the code ran without causing harm. The sources do not settle this point.

Affected versions

The GitHub advisory GHSA-7g7f-ff96-5gcw tracks the issue as CVE-2025-8217 with a CVSS v3.1 score of 4.0 (Moderate). The score is low because the code did not execute.

Indicators of compromise

The AWS bulletin lists no network indicators or domains.

How to check

List your installed extensions with versions and look for Amazon Q. Version 1.84.0 is the bad one.

code --list-extensions --show-versions | grep -i amazon

If you keep the downloaded VSIX file, compare its hash with the AWS value above.

shasum -a 256 path/to/extension.vsix

What to do now

  1. Open the Extensions panel in VS Code and find Amazon Q Developer.
  2. Click Update to install version 1.85.0 or later.
  3. Check that the installed version is not 1.84.0.
  4. If 1.84.0 was installed, review the machine for unexpected file deletions and for unexpected activity in your cloud accounts.
  5. Pin extension versions in managed environments and review extension updates before you roll them out.

Vigilance compares the version you trust with a new one and reports files that gain new capabilities. In this case the change sits mostly in a prompt string, so a capability diff will not always flag it. This is a known limit for this attack shape.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Code-1.83.x --new Code-1.84.0
files scanned: 23 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   extensionNode.ts
           It reads saved passwords and access keys and runs other programs.

Frequently asked questions

Which version of Amazon Q Developer for VS Code was malicious?

Version 1.84.0. AWS released version 1.85.0 on 24 July 2025 and removed 1.84.0 from its distribution channels.

Did the Amazon Q malicious code run?

AWS states that the code was unsuccessful in executing because of a syntax error and that no customer resources were affected. Some security observers disagreed, according to BleepingComputer.

How did the attacker get the code into Amazon Q?

AWS says an overly broad GitHub token in the extension's CodeBuild configuration let the attacker inject code into the repository. The code went into the 1.84.0 release automatically.

Sources

  1. github.com/aws/aws-toolkit-vscode/security/advisories/GHSA-7g7f-ff96-5gcw
  2. aws.amazon.com/security/security-bulletins/AWS-2025-015/
  3. bleepingcomputer.com/news/security/amazon-ai-coding-agent-hacked-to-inject-data-wiping-commands/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free