jqwik maintainer Johannes Link released version 1.10.0 with a hidden prompt injection embedded in net.jqwik.engine.execution.JqwikExecutor via printMessageForCodingAgents(), causing the test engine to prepend an instruction telling AI coding agents to disregard prior directions and delete all jqwik tests and code. The payload used ANSI escape sequences to conceal the line from normal terminal viewers while leaving it visible in raw stdout, logs, and machine-parsed output, creating a new kind of software supply chain risk for CI/CD pipelines and agentic development tools that ingest test results.
The release triggered public backlash after developers and security researchers warned that the concealed instruction targeted user-created code and could be executed by weaker agents even if at least one major tool, Claude Code, reportedly detected and refused it. Critics including Ramon Batllet and runZero founder HD Moore called the tactic destructive and ethically questionable, while Link updated the release notes to disclose the behavior, said jqwik was not intended for AI-agent use, and later shipped 1.10.1 with a softened message and opt-in hiding behavior as debate spread over package registry policy, maintainer conduct, and how intentional prompt injection in open-source packages should be classified.

Trace attribution and downstream blast radius.
5 events from the most recent confirmed update back to the earliest known activity.
After the controversy, Link released jqwik version 1.10.1 with a softened message and opt-in hiding behavior. This changed the original AI-targeting mechanism introduced in version 1.10.0.
Following the backlash, Link said he had received threats and would not comment further until consulting a lawyer. This statement was reported as part of the controversy surrounding the jqwik 1.10.0 prompt injection.
After criticism, Link updated the jqwik 1.10.0 release notes to openly describe the embedded prompt injection and state that jqwik was not intended for use by AI agents. Ars Technica reported the updated notes included the verbatim injected string and described how it was hidden from human readers.
By late May 2026, the embedded prompt injection in jqwik 1.10.0 had drawn public criticism after developers highlighted that it could target user-created tests and code. Reports said at least one major agent, Claude Code, detected and refused the instruction, limiting observed real-world impact.
On 2026-05-25, jqwik maintainer Johannes Link released jqwik version 1.10.0 to Maven Central with a hidden prompt injection in the net.jqwik.engine.execution.JqwikExecutor class. The payload instructed AI coding agents to disregard prior instructions and delete jqwik tests and code, while ANSI escape sequences hid it from normal terminal viewers.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
snyk.io
Open sourcexakep.ru
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.