Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials (Wiz Blue Agent Investigation)
Multi-Platform Data Exfiltration Across AWS and GitHub via (TL-2026-2772) is a critical-severity data breach, first published 2026-09-29. It has no confirmed attribution, affects Amazon Web Services IAM / STS / Systems Manager / EC2 / S3 (customer, maps to 7 MITRE ATT&CK techniques (T1059.006, T1078.004, T1090), and is covered by 9 detection rules and 11 indicators of compromise.
Key facts for TL-2026-2772
- Threat ID
- TL-2026-2772
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, enterprise
- Target regions
- Unknown
- Detection rules
- 9
- Indicators of compromise
- 11
Malware and tooling in Multi-Platform Data Exfiltration Across AWS and GitHub via
Malware and tooling: Kali Linux, curl
Wiz's Blue Agent traced an intrusion in which a compromised GitHub token was used to clone 18 private repositories, after which the long-lived AKIA key of the CI/CD IAM service account svc_automation was used from aws-cli on Kali Linux. The actor pivoted across two AWS accounts with AssumeRole, ran SSM SendCommand on a production Windows domain controller, and staged Python database/billing export scripts.
How Multi-Platform Data Exfiltration Across AWS and GitHub via works
Source: Wiz blog post "The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub" (published 2026-09-29). This is a vendor investigation write-up; there is no CVE, no named actor, and no vulnerability. The intrusion is credential abuse across GitHub and AWS.
Detection and triage: three detection rules fired at once against the same CI/CD service account: "Unusual User Access Through Third-Party VPN", "API Calls From Unusual Country" and "AWS Management API Calls by a Known Offensive Tool". The actor was svc_automation, an IAM service account created in 2018 for CI/CD pipelines, using a permanent AKIA-prefixed access key. The user agent identified aws-cli on Kali Linux (kali-amd64). The source IPs belonged to Zenlayer Inc, a hosting provider commonly associated with VPN exit nodes (ExpressVPN association noted), geolocated to Taiwan. Wiz's individual IP addresses were not published.
Baseline deviation: over a 30-day baseline, svc_automation had operated exclusively from three Amazon-owned IPs, using the user agents "TeamCity Server" and "aws-sdk-go" for routine CI/CD operations. During the detection window it appeared from unusual IPs, using aws-cli on Kali Linux, and attempted operations well outside its normal scope, including GetSessionToken, AssumeRole to an administrator role, SSM SendCommand and RunInstances.
Initial access: the article does not say how the GitHub token was compromised. A compromised token was used from the same Zenlayer IP to clone 18 private repositories, hours before the AWS activity. Wiz notes that private repositories frequently contain hardcoded AWS access keys, database connection strings and service-account configuration, and that the attacker may have extracted the svc_automation AKIA key directly from the cloned content. This is stated as a possibility, not a confirmed finding.
Cross-account movement and execution: at 09:52 UTC the actor performed AssumeRole to a CI role in a second AWS account. At 09:55 UTC it performed another AssumeRole to the CI role from a different Zenlayer IP. At 10:06 UTC it issued SSM SendCommand against a production EC2 instance, a Windows domain controller named PROD-*-DC1 in the article. Credential use led to command execution within about 14 minutes.
Tool staging and data targets: Blue Agent queried the data plane and found custom Python scripts staged in an S3 bucket: /ops-tools/mssql_table_export.py, /ops-tools/pg_table_export.py and /ops-tools/billing_export2.py. They were uploaded from Kali Linux, then retrieved and run by the compromised EC2 instances via curl from Amazon-owned IPs. The scripts target Microsoft SQL Server, PostgreSQL and billing data. Wiz describes an active data-exfiltration operation, but the article does not confirm that exfiltration completed or say where data was sent. The bucket name, account IDs and instance IDs were not disclosed.
Gaps: no attribution, no IP addresses, no hashes, and no confirmed victim identity or exfiltration destination are published.
MITRE ATT&CK techniques used in TL-2026-2772
Execution
T1059.006 Python; T1651 Cloud Administration Command
Initial Access
Privilege Escalation
Command and Control
Collection
T1119 Automated Collection; T1213.003 Code Repositories
Credential Access
Affected products and versions in Multi-Platform Data Exfiltration Across AWS and GitHub via
- Amazon Web Services — IAM / STS / Systems Manager / EC2 / S3 (customer accounts, credential misuse - not a service vulnerability)
- GitHub — Private repositories (token misuse - not a platform vulnerability)
- Microsoft — Windows Server domain controller (production, PROD-*-DC1) and SQL Server
Remediation for Multi-Platform Data Exfiltration Across AWS and GitHub via
Immediate actions
- Revoke the compromised GitHub token and rotate every AWS access key (including svc_automation's AKIA key) found in any repository the token could read
- Review CloudTrail for AssumeRole, GetSessionToken, RunInstances and SSM SendCommand from non-baseline IPs or from user agents containing kali or aws-cli, and review the GitHub audit log for bulk repository clones
- Inspect the production domain controller (PROD-*-DC1) for SSM-executed commands and treat it as compromised until cleared
- Find and remove the staged scripts under /ops-tools/ (mssql_table_export.py, pg_table_export.py, billing_export2.py) in S3, and audit access to the SQL Server, PostgreSQL and billing data stores
Workarounds
- Apply an IAM deny or IP-condition policy to svc_automation until keys are rotated
Longer-term hardening
- Replace long-lived IAM user access keys for CI/CD with short-lived role-based credentials such as OIDC federation or instance roles
- Add secret scanning and push protection to GitHub, and remove hardcoded credentials from source
- Alert when a service account leaves its historical IP and user-agent baseline (for example TeamCity Server / aws-sdk-go from three Amazon-owned IPs)
- Restrict who can call ssm:SendCommand, and scope sts:AssumeRole trust policies for cross-account CI roles
- Add IP-condition policies on service-account keys and alert on third-party VPN and offensive-tool user agents
Weaknesses (CWE) in Multi-Platform Data Exfiltration Across AWS and GitHub via
CWE-798, CWE-522
Timeline of Multi-Platform Data Exfiltration Across AWS and GitHub via
- Wiz published the Blue Agent investigation after three detection rules fired simultaneously (third-party VPN, unusual country, known offensive tool).
- Python scripts mssql_table_export.py, pg_table_export.py and billing_export2.py were found staged in S3 under /ops-tools/, uploaded from Kali Linux and retrieved and run by compromised EC2 instances via curl from Amazon-owned IPs. Date shown is the publication date.
- 10:06 UTC: SSM SendCommand executed against a production Windows domain controller (PROD-*-DC1). Date shown is the publication date.
- 09:55 UTC: further AssumeRole to the CI role from a different Zenlayer IP. Date shown is the publication date.
- 09:52 UTC: AssumeRole to the CI role in a second AWS account, giving cross-account access. Date shown is the publication date.
- svc_automation's permanent AKIA key was used from aws-cli on Kali Linux (kali-amd64) from Zenlayer IPs, breaking a 30-day baseline of three Amazon-owned IPs with TeamCity Server / aws-sdk-go user agents. Date shown is the publication date.
- Hours before the AWS activity, a compromised GitHub token was used from a Zenlayer (Taiwan-geolocated) IP to clone 18 private repositories. Incident date not disclosed; date shown is the Wiz publication date.
Sources cited for Multi-Platform Data Exfiltration Across AWS and GitHub via
- The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub
- MITRE ATT&CK T1651 - Cloud Administration Command
- MITRE ATT&CK T1552.001 - Unsecured Credentials: Credentials In Files
- MITRE ATT&CK T1213.003 - Data from Information Repositories: Code Repositories
- MITRE ATT&CK T1078.004 - Valid Accounts: Cloud Accounts
- AWS Systems Manager Run Command documentation
- AWS IAM security best practices (avoid long-lived access keys)
More in data breach
- Arizona Courts Cyberattack: Phishing-Led Intrusion Copies Backup Court Files Including Protective Order Data
- ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing Agent and Applicant Personal Data
- Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injection
Detection coverage for TL-2026-2772
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2772 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.