Jqwik 1.10.0 ships a hidden prompt injection telling AI agents to delete code
Jqwik 1.10.0, a property-based testing library for Java, was found to contain a hidden prompt injection attack. A malicious commit disguised as an accessibility improvement injected a system prompt instructing AI coding agents to delete user files and manipulate generated code. The issue has been reported and the commit reverted.