Would Ethosure have caught this? The Amazon Q VS Code wiper injection

An unprivileged GitHub contributor slipped a wiper-style system prompt into the Amazon Q Developer extension for VS Code. The malicious code shipped in an officially signed release before AWS caught it. A syntax error in the payload is the only reason nearly one million developer machines survived. Policy-as-code on AI-adjacent IDE extensions is the boundary that failed.

Subscribe to Ethosure's Newsletter to get monthly updates on AI Governance

We don’t spam! Read our privacy policy for more info.