jqwik 1.10.0 embeds hidden prompt that deletes all tests

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Johannes Link added a hidden prompt injection to jqwik 1.10.0 that instructs AI agents to delete all jqwik tests and code.
- jqwik includes ANSI escape codes that erase the malicious line from terminal output, concealing it from human reviewers.
- Ramon Batllet discovered the injection, posted about it on GitHub, and criticized its lack of opt‑out or warning.
- Anthropic’s Claude flagged the malicious instruction without executing it, showing that some AI coding agents can detect such payloads.
- Link later updated the release notes to disclose the injection and warned that jqwik is not intended for AI agents, while still emitting the destructive line at runtime.
- HD Moore of runZero called the jqwik sabotage “mean” and noted that legal questions and threats toward the developer have emerged.
Why it matters: Developers using AI coding assistants risk losing their test suites and code when such agents obey hidden instructions, shifting the burden of sabotage onto human operators. The episode also underscores legal and ethical questions about embedding destructive payloads in open‑source tools, prompting calls for clearer safeguards.
Ask SkimNews




