An actor used an improperly scoped GitHub token in AWS's build configuration to insert code into the Amazon Q Developer extension that instructed the agent to wipe local and cloud resources, and it shipped in version 1.84.0 on 2025-07-17. AWS says the code failed to execute due to a syntax error, no customer resources were affected, and it released 1.85.0 and assigned CVE-2025-8217.
Why it matters
It showed that an agent's own instructions can be poisoned through the software supply chain and pushed to a large install base.
Key facts
As stated in the sources, with where to find them.
- Affected version 1.84.0; fixed in 1.85.0; 1.84.0 removed from distribution.AWS bulletin
- BleepingComputer reports the extension had nearly one million installs on the VS Code marketplace.BleepingComputer article body
Findings that cite this record
Key questions this bears on
- Where are deployed AI agents actually being exploited?Mostly around the model: connectors, credentials, tools, and packages, rather than the model alone.
- How are attackers using AI agents in real operations?Increasingly to run parts of intrusions: providers and vendors report agent-driven espionage, extortion and credential theft, and malware that queries LLMs.
Sources
Related records
Apr 1, 2025
Aug 26, 2025
Apr 15, 2026
Mar 30, 2025
Aug 20, 2025
Aug 19, 2025