step-security · Crawled Sep 1, 2026

Runtime Security for AWS CodeBuild-Hosted GitHub Actions Runners

1 CVEs
Read original article ↗

AI Summary

In July 2025, a threat actor exploited a memory-dumping technique in AWS CodeBuild environments to steal source repository access tokens, which were then used to access repositories for the AWS Toolkit for Visual Studio Code and the AWS SDK for .NET. The attack occurred when a malicious pull request triggered a build that read and exfiltrated tokens from process memory. This incident highlights the risk of credential theft in CI/CD pipelines, particularly when using AWS CodeBuild-hosted GitHub Actions runners that assume IAM roles with broad access. The technique used is linked to CVE-2025-8217 and resembles tactics seen in other compromises such as the tj-actions/changed-files incident.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 1 techniques