Preliminary research
CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild
AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
An unanchored AWS CodeBuild actor-ID regular expression accepts an attacker GitHub ID containing the trusted ID as a substring. A pull-request build then exposes privileged credentials from process memory, enabling takeover of AWS SDK repositories and their software supply chain.
Record
- Researcher
- Yuval Avrahami and Nir Ohfeld
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Yuval Avrahami and Nir Ohfeld, first published at the original source. Preserved copies are kept so the citation survives its host.