Multi-Platform Data Exfiltration Across AWS and GitHub via Stolen GitHub Token and Hardcoded AWS Credentials (Wiz Blue Agent Investigation)

Multi-Platform Data Exfiltration Across AWS and GitHub via (TL-2026-2772) is a critical-severity data breach, first published 2026-09-29. It has no confirmed attribution, affects Amazon Web Services IAM / STS / Systems Manager / EC2 / S3 (customer, maps to 7 MITRE ATT&CK techniques (T1059.006, T1078.004, T1090), and is covered by 9 detection rules and 11 indicators of compromise.

Key facts for TL-2026-2772

Threat ID
TL-2026-2772
Severity
CRITICAL
Status
ACTIVE
Category
DATA_BREACH
First published
2026-09-29
Last reviewed
2026-09-29
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, enterprise
Target regions
Unknown
Detection rules
9
Indicators of compromise
11

Malware and tooling in Multi-Platform Data Exfiltration Across AWS and GitHub via

Malware and tooling: Kali Linux, curl

Wiz's Blue Agent traced an intrusion in which a compromised GitHub token was used to clone 18 private repositories, after which the long-lived AKIA key of the CI/CD IAM service account svc_automation was used from aws-cli on Kali Linux. The actor pivoted across two AWS accounts with AssumeRole, ran SSM SendCommand on a production Windows domain controller, and staged Python database/billing export scripts.

How Multi-Platform Data Exfiltration Across AWS and GitHub via works

Source: Wiz blog post "The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub" (published 2026-09-29). This is a vendor investigation write-up; there is no CVE, no named actor, and no vulnerability. The intrusion is credential abuse across GitHub and AWS.

Detection and triage: three detection rules fired at once against the same CI/CD service account: "Unusual User Access Through Third-Party VPN", "API Calls From Unusual Country" and "AWS Management API Calls by a Known Offensive Tool". The actor was svc_automation, an IAM service account created in 2018 for CI/CD pipelines, using a permanent AKIA-prefixed access key. The user agent identified aws-cli on Kali Linux (kali-amd64). The source IPs belonged to Zenlayer Inc, a hosting provider commonly associated with VPN exit nodes (ExpressVPN association noted), geolocated to Taiwan. Wiz's individual IP addresses were not published.

Baseline deviation: over a 30-day baseline, svc_automation had operated exclusively from three Amazon-owned IPs, using the user agents "TeamCity Server" and "aws-sdk-go" for routine CI/CD operations. During the detection window it appeared from unusual IPs, using aws-cli on Kali Linux, and attempted operations well outside its normal scope, including GetSessionToken, AssumeRole to an administrator role, SSM SendCommand and RunInstances.

Initial access: the article does not say how the GitHub token was compromised. A compromised token was used from the same Zenlayer IP to clone 18 private repositories, hours before the AWS activity. Wiz notes that private repositories frequently contain hardcoded AWS access keys, database connection strings and service-account configuration, and that the attacker may have extracted the svc_automation AKIA key directly from the cloned content. This is stated as a possibility, not a confirmed finding.

Cross-account movement and execution: at 09:52 UTC the actor performed AssumeRole to a CI role in a second AWS account. At 09:55 UTC it performed another AssumeRole to the CI role from a different Zenlayer IP. At 10:06 UTC it issued SSM SendCommand against a production EC2 instance, a Windows domain controller named PROD-*-DC1 in the article. Credential use led to command execution within about 14 minutes.

Tool staging and data targets: Blue Agent queried the data plane and found custom Python scripts staged in an S3 bucket: /ops-tools/mssql_table_export.py, /ops-tools/pg_table_export.py and /ops-tools/billing_export2.py. They were uploaded from Kali Linux, then retrieved and run by the compromised EC2 instances via curl from Amazon-owned IPs. The scripts target Microsoft SQL Server, PostgreSQL and billing data. Wiz describes an active data-exfiltration operation, but the article does not confirm that exfiltration completed or say where data was sent. The bucket name, account IDs and instance IDs were not disclosed.

Gaps: no attribution, no IP addresses, no hashes, and no confirmed victim identity or exfiltration destination are published.

MITRE ATT&CK techniques used in TL-2026-2772

Execution

T1059.006 Python; T1651 Cloud Administration Command

Initial Access

T1078.004 Cloud Accounts

Privilege Escalation

T1078.004 Cloud Accounts

Command and Control

T1090 Proxy

Collection

T1119 Automated Collection; T1213.003 Code Repositories

Credential Access

T1552.001 Credentials In Files

Affected products and versions in Multi-Platform Data Exfiltration Across AWS and GitHub via

  • Amazon Web Services — IAM / STS / Systems Manager / EC2 / S3 (customer accounts, credential misuse - not a service vulnerability)
  • GitHub — Private repositories (token misuse - not a platform vulnerability)
  • Microsoft — Windows Server domain controller (production, PROD-*-DC1) and SQL Server

Remediation for Multi-Platform Data Exfiltration Across AWS and GitHub via

Immediate actions

  • Revoke the compromised GitHub token and rotate every AWS access key (including svc_automation's AKIA key) found in any repository the token could read
  • Review CloudTrail for AssumeRole, GetSessionToken, RunInstances and SSM SendCommand from non-baseline IPs or from user agents containing kali or aws-cli, and review the GitHub audit log for bulk repository clones
  • Inspect the production domain controller (PROD-*-DC1) for SSM-executed commands and treat it as compromised until cleared
  • Find and remove the staged scripts under /ops-tools/ (mssql_table_export.py, pg_table_export.py, billing_export2.py) in S3, and audit access to the SQL Server, PostgreSQL and billing data stores

Workarounds

  • Apply an IAM deny or IP-condition policy to svc_automation until keys are rotated

Longer-term hardening

  • Replace long-lived IAM user access keys for CI/CD with short-lived role-based credentials such as OIDC federation or instance roles
  • Add secret scanning and push protection to GitHub, and remove hardcoded credentials from source
  • Alert when a service account leaves its historical IP and user-agent baseline (for example TeamCity Server / aws-sdk-go from three Amazon-owned IPs)
  • Restrict who can call ssm:SendCommand, and scope sts:AssumeRole trust policies for cross-account CI roles
  • Add IP-condition policies on service-account keys and alert on third-party VPN and offensive-tool user agents

Weaknesses (CWE) in Multi-Platform Data Exfiltration Across AWS and GitHub via

CWE-798, CWE-522

Timeline of Multi-Platform Data Exfiltration Across AWS and GitHub via

  • Wiz published the Blue Agent investigation after three detection rules fired simultaneously (third-party VPN, unusual country, known offensive tool).
  • Python scripts mssql_table_export.py, pg_table_export.py and billing_export2.py were found staged in S3 under /ops-tools/, uploaded from Kali Linux and retrieved and run by compromised EC2 instances via curl from Amazon-owned IPs. Date shown is the publication date.
  • 10:06 UTC: SSM SendCommand executed against a production Windows domain controller (PROD-*-DC1). Date shown is the publication date.
  • 09:55 UTC: further AssumeRole to the CI role from a different Zenlayer IP. Date shown is the publication date.
  • 09:52 UTC: AssumeRole to the CI role in a second AWS account, giving cross-account access. Date shown is the publication date.
  • svc_automation's permanent AKIA key was used from aws-cli on Kali Linux (kali-amd64) from Zenlayer IPs, breaking a 30-day baseline of three Amazon-owned IPs with TeamCity Server / aws-sdk-go user agents. Date shown is the publication date.
  • Hours before the AWS activity, a compromised GitHub token was used from a Zenlayer (Taiwan-geolocated) IP to clone 18 private repositories. Incident date not disclosed; date shown is the Wiz publication date.

Sources cited for Multi-Platform Data Exfiltration Across AWS and GitHub via

More in data breach

Detection coverage for TL-2026-2772

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2772 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats