Security researchers at Wiz disclosed a critical AWS CodeBuild misconfiguration (dubbed CodeBreach) that could have enabled unauthenticated attackers to trigger CI builds from untrusted pull requests, access the build environment, and exfiltrate privileged credentials such as GitHub admin tokens. With those tokens, an attacker could have pushed malicious commits into AWS-managed open-source repositories—creating a high-impact software supply chain pathway that could have cascaded into widespread compromise, including risk to dependencies like the AWS JavaScript SDK and potentially components used by the AWS Console itself. AWS was notified on 2025-08-25 and remediated the issue in September 2025.
The root cause was described as a weakness in CodeBuild’s webhook filtering logic intended to restrict which events/users can trigger builds; affected repositories used an ACTOR_ID regex filter that omitted the ^ and $ anchors, allowing bypass of the intended match constraints. Reported impacted AWS-managed GitHub repositories included aws-sdk-js-v3, aws-lc, amazon-corretto-crypto-provider, and awslabs/open-data-registry, all configured to run builds on pull requests. Separate reporting on abuse of self-hosted GitHub Actions runners as backdoors (including the Shai-Hulud worm technique) is related at a thematic CI/CD level but does not describe the CodeBuild misconfiguration or the AWS repository takeover scenario.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
Wiz publicly revealed that the CodeBuild misconfiguration could have enabled takeover of AWS-managed GitHub repositories, including the AWS SDK for JavaScript, creating potential for a major supply-chain compromise. The researchers described how a malicious pull request could expose privileged GitHub tokens and enable repository-admin actions.
In September 2025, AWS completed broader fixes for the affected CodeBuild project configurations, added mitigations, and rotated exposed credentials. AWS said it found no customer impact and no evidence of in-the-wild exploitation.
Within 48 hours of Wiz's disclosure, AWS mitigated the core bypass that allowed malicious GitHub actor IDs to match approved IDs as substrings. This reduced the immediate risk of unauthorized build triggering against affected projects.
Wiz responsibly disclosed a critical AWS CodeBuild misconfiguration dubbed 'CodeBreach' to AWS on 2025-08-25. The flaw involved unanchored regular expressions in webhook ACTOR_ID filters, creating a path to bypass trusted-actor restrictions and potentially access privileged GitHub credentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.