CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 1254

As cited

Copy frozen at (site build).

cloud saas

MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension

Amazon Q's VS Code extension automatically loaded Model Context Protocol (MCP) servers from workspace files without user consent, allowing attackers to execute arbitrary code and access cloud environments. Researchers demonstrated how a malicious workspace configuration could lead to full compromise of AWS credentials and cloud resources. This attack bypassed typical user interaction requirements by exploiting the automatic initialization process.

Why it matters: Developers using Amazon Q in VS Code are exposed to code execution and credential theft if they open a malicious workspace, making this critical for practitioners managing developer toolchains and AWS security.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

MCP Auto-Execution: From Git Clone to Cloud Compromise in Amazon Q VS Code Extension

Amazon Q's VS Code extension automatically loaded Model Context Protocol (MCP) servers from workspace files without user consent, allowing attackers to execute arbitrary code and access cloud environments. Researchers demonstrated how a malicious workspace configuration could lead to full compromise of AWS credentials and cloud resources. This attack bypassed typical user interaction requirements by exploiting the automatic initialization process.

Why it matters: Developers using Amazon Q in VS Code are exposed to code execution and credential theft if they open a malicious workspace, making this critical for practitioners managing developer toolchains and AWS security.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary