Threat · curated 29 Jun 2026
Amazon Q VS Extension Flaw Leads to Cloud Credential Theft
First reported wiz.io
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
AI coding assistants and their MCP integrations expand the attack surface, allowing a poisoned repository to trigger code execution and cloud credential theft on a developer's machine.
A vulnerability in the Amazon Q Visual Studio extension could let adversaries plant a malicious repository that executes arbitrary code and steals cloud credentials, highlighting growing MCP-related risk.