Autopsy Series
Would Ethosure have caught this? The Amazon Q VS Code wiper injection
An unprivileged GitHub contributor slipped a wiper-style system prompt into the Amazon Q Developer extension for VS Code. The malicious code shipped in an officially signed release before AWS caught it. A syntax error in the payload is the only reason nearly one million developer machines survived. Policy-as-code on AI-adjacent IDE extensions is the boundary that failed.
