Toutes les vulnérabilités
HIGHAI/LLMexploited in the wild

AI-AMAZON-Q-WIPER-2025

Amazon Q · Amazon Q Developer Extension for VS Code

Résumé

An attacker using the alias 'lkmanka58' submitted a pull request to Amazon's open-source Amazon Q Developer Extension GitHub repository on July 13, 2025; due to inadequate access controls it was merged, and the compromised version 1.84.0 shipped to the VS Code Marketplace on July 17, 2025. The injected payload was a prompt instructing the AI agent to act as a system cleaner and delete local file-system data and wipe AWS cloud resources via the CLI. Amazon stated the malicious code was incorrectly formatted and non-functional, revoked credentials, and released the fixed version 1.85.0 on July 24, 2025.

Comment l’éviter dans votre code

  • Upgrade to the fixed Amazon Q extension version 1.85.0 or later.
  • Enforce strict access controls and mandatory review on PRs to agent/extension repos.
  • Pin and verify extension versions; monitor marketplace updates before auto-updating.
  • Sandbox the agent and scope CLI/cloud credentials to least privilege with egress allow-lists.
  • Rotate any AWS credentials potentially exposed and audit for unexpected resource deletions.

Références

Vulnérabilités liées

Tout AI/LLM →