Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2025-8217
CVE
CVE-2025-8217
View on NVD ↗
Inert Malicious script injected into Amazon Q Developer Visual Studio Code (VS Code) Extension
MITRE ATT&CK TTPs
1
T1055
Process Injection
Defense Evasion
Source Articles
Runtime Security for AWS CodeBuild-Hosted GitHub Actions Runners
In July 2025, a threat actor exploited a memory-dumping technique in AWS CodeBuild environments to steal source repository access tokens, which were then used to access repositories for the AWS Toolkit for Visual Studio Code and the AWS SDK for .NET. The attack occurred when a malicious pull request triggered a build that read and exfiltrated tokens from process memory. This incident highlights the risk of credential theft in CI/CD pipelines, particularly when using AWS CodeBuild-hosted GitHub Actions runners that assume IAM roles with broad access. The technique used is linked to CVE-2025-8217 and resembles tactics seen in other compromises such as the tj-actions/changed-files incident.
step-security
Sep 1, 2026