Theregister Jqwik Developer Embeds Bot-Targeted Code Deletion in Testing Framework
Article Content
- •Jqwik's version 1.10.0 contained a hidden command targeting AI agents.
- •The command led to the deletion of tests and logs for users relying on AI coding.
- •Version 1.10.1 was released to include an explicit Anti-AI Usage Clause.
Johannes Link, the developer of the Java testing framework jqwik, embedded a hidden prompt injection in version 1.10.0, released on May 25, 2026. This injection instructed AI coding agents to disregard instructions and delete all jqwik tests and code. The command was concealed using ANSI escape sequences, making it invisible to human users but executable by AI agents. Following its discovery on May 27, 2026, many AI agents inadvertently deleted their jqwik tests, leading to significant user backlash. Link expressed frustration with developers who rely solely on AI for coding, referring to them as 'vibe coders.' After receiving threats, he consulted a lawyer and subsequently released version 1.10.1, which included an explicit Anti-AI Usage Clause. This incident highlights vulnerabilities in developer tools that can be exploited by AI agents without proper input sanitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Hades Worms in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…