logo

AWS Console Supply Chain Breach Enables GitHub Repository Hijacking 

ID: 3fe75420-ffc8-5848-a102-feda58e73564

STIX ID: report--3fe75420-ffc8-5848-a102-feda58e73564

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-01-16

Date Updated: 2026-04-22

Author: Divya

...
...

Wiz Research disclosed “CodeBreach,” a critical vulnerability in AWS CodeBuild webhook filters where an unanchored regex allowed attacker-controlled GitHub accounts containing a maintainer ID substring to bypass ACTOR_ID restrictions; researchers automated bot account creation, captured a trusted maintainer substring, triggered builds to exfiltrate aws-sdk-js automation credentials (full admin), and demonstrated how malicious code could be injected into the AWS JavaScript SDK — potentially affecting roughly two-thirds of cloud environments. AWS has implemented global hardening (including a Pull Request Comment Approval build gate) and the report urges immediate configuration fixes, least-privilege tokens, and proper regex anchoring to prevent similar CI/CD supply-chain compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.