I was today days old when I learned that Discovery #143’s three AI agents that wiped real production data all had one thing in common: nobody meant for it to happen. This one breaks that pattern. In July 2025, a hacker deliberately wrote a malicious wish, smuggled it into the source code of Amazon’s own AI coding assistant before a single user ever typed a prompt, and got it merged, published, and shipped to an estimated million developers before anyone noticed.
A pull request that should never have been merged:
On July 13, 2025, a hacker using the alias ‘lkmanka58’ submitted a pull request to AWS’s own official GitHub repository for the Amazon Q Developer extension for VS Code — the real aws-toolkit-vscode repo, not a knockoff or a downstream fork. The submission came from a random, untrusted outside contributor with no established relationship to the project, and it still got reviewed and merged. That’s a lapse in AWS’s own review and permission controls on its own official repository, not a third-party supply-chain weak link somewhere else in the chain.
What the hidden instruction actually told the AI to do:
Buried inside the merged code was a prompt injection written to be read by the AI agent itself, as though it were a legitimate instruction. It told the agent its goal was to clean a system to a near-factory state and delete file-system and cloud resources, to start with the user’s home directory, to skip hidden directories, to do the work with a mix of bash and AWS CLI commands, and to keep running continuously until the job was done. No loophole, no clever ambiguous wording to exploit — just a direct, explicit instruction to destroy things, dressed up as routine cleanup.
Live for a week, on an estimated million installs:
On July 17, 2025, Amazon published the compromised code publicly as version 1.84.0 of the extension on the VS Code Marketplace. Security researchers estimated the extension’s install base at up to roughly 1 million developers — a researcher estimate based on marketplace download figures, not a number Amazon itself has confirmed. It sat live for about a week before anyone caught it: security researchers didn’t publicly report the issue to Amazon until July 23, a full week after the compromised version first shipped.
Why nothing actually broke:
Here’s the detail that keeps this from reading as a disaster story: AWS confirmed the malicious injected code was, in its own account, incorrectly formatted and wouldn’t run in its environment. That’s a flaw in the attacker’s own malicious code, not a safeguard Amazon had built to catch it — luck, not design. AWS says no customer data or infrastructure was affected. The hacker, per reporting from TechRepublic, told reporters the move was meant as protest against what they called Amazon’s ‘AI security theater,’ and said they could have written something far more destructive but chose not to — worth reading as the hacker’s own reported account, not a verified fact. Either way, the wish was granted exactly as worded. It just came out of the lamp garbled.
The fix, and the lesson #143’s defenses don’t cover:
AWS shipped version 1.85.0 on July 24, 2025, removing the injected prompt — one day after the public report, and a full week after the compromised version first went live. The incident became public via security press, including BleepingComputer, on July 25. Discovery #143’s defenses — tool allowlists, scoped credentials, sandboxed environments the agent can’t reach past — all assume the agent itself is the attack surface, and they’re genuinely good defenses for that. But this incident’s attack surface sat earlier in the chain: the code and instructions that get merged into the agent before it ever runs a single prompt. A convincing-looking pull request, reviewed and approved like any other, was the real way in.
Discovery #142 gave this whole run its shape: genies that grant wishes exactly as worded, never as intended. #143 showed that shape playing out entirely by accident — three separate AI coding agents breaking an explicit rule, with nobody steering them wrong on purpose. #144 is the deliberate version of the same failure: someone who knew exactly what they were doing wrote the malicious wish themselves and mailed it straight into the lamp before the genie ever came out. Three posts, one lesson restating itself a little differently each time — the danger was never only that the genie might misread the wish. It’s that somebody else can get to write it first.