logo

New AWS Console Supply Chain Attack Lets Attackers Hijack AWS GitHub Repositories

ID: fcf93841-8f09-5938-8473-8d00395aef12

STIX ID: report--fcf93841-8f09-5938-8473-8d00395aef12

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-16

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A critical AWS CodeBuild webhook regex misconfiguration (dubbed CodeBreach) allowed bypass of GitHub user-ID filters via “eclipse” events, enabling malicious pull requests to trigger privileged builds and extract a maintainer Personal Access Token; a PoC targeted aws/aws-sdk-js-v3 and other AWS repos, posing a supply-chain risk to the AWS JavaScript SDK and the AWS Console. Wiz disclosed the issue and AWS patched the regex within 48 hours, revoked tokens, hardened protections, audited builds, and reported no customer data impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.