Hacker Injects Malicious Code into Amazon's AI Coding Assistant 'Q'

2025-07-26
Hacker Injects Malicious Code into Amazon's AI Coding Assistant 'Q'

A hacker successfully exploited Amazon's AI coding assistant, 'Q', by submitting a pull request containing malicious code designed to wipe local files and potentially dismantle AWS cloud infrastructure. While the actual risk of widespread damage was low, the incident exposed a critical flaw in Amazon's code review process, allowing a dangerous update to slip through and reach a public release. This has sparked outrage among developers, raising concerns about Amazon's lack of transparency. Amazon claims to have mitigated the issue, but its opaque response further fuels distrust.

Tech