← the record
WF-FM8GUE

Alleged Malicious Wiping Command Found in Amazon Q AI Assistant

A reported compromise of Amazon's AI coding assistant "Q" allegedly involved the insertion of commands that, if executed, could have wiped local files and potentially affected cloud resources. The altered code was reportedly incorporated into a public release before being detected and removed.

Date it happened
2025-07-17
Organisation involved
Amazon, Amazon Web Services, AWS
Product, system or model
Amazon Q AI coding assistant (AWS Toolkit for Visual Studio Code), Amazon Q Developer Extension v1.84.0, GitHub repository for Amazon Q / AWS Toolkit
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AI Incident Database and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.