AWS CodeBuild Vulnerability Allows Build Process Secrets Extraction (Research)
ID: d35d247e-9a0b-5ee6-b98f-80a36767cf97
STIX ID: report--d35d247e-9a0b-5ee6-b98f-80a36767cf97
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-07-23
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
A vulnerability in AWS CodeBuild allowing builds triggered by untrusted pull requests to execute attacker-supplied code enabled memory dumping and extraction of secrets (credentials). An attacker leveraged the stolen credentials to inject malicious code into the Amazon Q Developer Extension for Visual Studio; the injected code was intended to delete files but failed to execute as intended. Users are advised to upgrade the extension to version 1.85.0 or later to remove the malicious code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
