Back to Blog
CVE-2026-12957/12958: Amazon Q Developer — Cloud Credential Theft via Malicious Repos (April 2026)
vulnerabilities

CVE-2026-12957/12958: Amazon Q Developer — Cloud Credential Theft via Malicious Repos (April 2026)

breachwire TeamJun 29, 20262 min read

CVE-2026-12957/12958 — Amazon Q Developer Extension

CVE-2026-12957 and CVE-2026-12958 are high-severity vulnerabilities in the Amazon Q Developer extension for Visual Studio Code. These flaws allowed attackers to execute arbitrary, attacker-controlled commands when a developer opened a malicious repository, enabling theft of cloud credentials and API keys. No evidence of active exploitation has been reported, but the risk profile is critical due to the potential for lateral movement into cloud infrastructure.

Attack Vector

Attackers crafted repositories containing malicious code that triggered upon opening in Visual Studio Code with the Amazon Q Developer extension enabled. No user interaction beyond opening the repository was required. The exploit leveraged the extension’s elevated privileges to execute background commands, harvesting AWS credentials and API tokens from the developer’s environment. This could result in compromise of both the local development machine and associated AWS accounts. No specific IOCs have been published, but any unexpected command execution or credential access following repository access should be investigated.

Who Is at Risk

All organizations and developers using the Amazon Q Developer extension for Visual Studio Code prior to the April 2026 patch are at risk. This includes any AWS customers whose developers use VS Code with the extension installed. Both individual and enterprise AWS environments may be affected if credentials are exposed.

Patch & Mitigate

  • Patch: Update the Amazon Q Developer extension for Visual Studio Code to the latest version released after April 2026. Apply immediately.
  • Workaround: Avoid opening untrusted or unfamiliar repositories in VS Code until patched. Restrict extension permissions where possible.
  • Detect: Review developer machine logs for unexpected command execution events after opening new repositories. Monitor AWS CloudTrail for anomalous credential usage or new API key activity.

MITRE ATT&CK

  • TA0005 — Defense Evasion: Attackers leveraged trusted extensions to bypass security controls and execute code.
  • TA0006 — Credential Access: The exploit directly targeted theft of cloud credentials and API keys from developer environments.

Source: https://www.securityweek.com/amazon-q-flaw-enabled-cloud-credential-theft-via-malicious-repositories/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: