New AWS Console Supply Chain Attack Lets Attackers Hijack AWS GitHub Repositories
ID: fcf93841-8f09-5938-8473-8d00395aef12
STIX ID: report--fcf93841-8f09-5938-8473-8d00395aef12
Feed Name: cybersecurityNews.com
A critical AWS CodeBuild webhook regex misconfiguration (dubbed CodeBreach) allowed bypass of GitHub user-ID filters via “eclipse” events, enabling malicious pull requests to trigger privileged builds and extract a maintainer Personal Access Token; a PoC targeted aws/aws-sdk-js-v3 and other AWS repos, posing a supply-chain risk to the AWS JavaScript SDK and the AWS Console. Wiz disclosed the issue and AWS patched the regex within 48 hours, revoked tokens, hardened protections, audited builds, and reported no customer data impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
