An AI Coding Tool Built Into Millions of Developer Setups Had a Flaw That Could Hand Hackers Your Cloud Keys

A security hole in Amazon's AI coding assistant let criminals steal cloud credentials just by getting a developer to open a poisoned folder. It's patched, but the attack method is spreading.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration for the story: An AI Coding Tool Built Into Millions of Developer Setups Had a Flaw That Could Hand Hackers
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Amazon Web Services patched a high-severity flaw tracked as CVE-2026-12957 in its Amazon Q Developer coding assistant in 2025.
  • The bug let criminals steal a developer's cloud credentials, the digital keys that control an entire company's cloud infrastructure, without the developer doing anything beyond opening a folder.
  • Researchers at cloud security firm Wiz Research discovered and reported the vulnerability to AWS.
  • AWS fixed the issue in Language Server version 1.65.0; anyone running that version or later is protected.
  • Identical design weaknesses have now turned up in at least three other popular AI coding tools: Claude Code, Cursor, and Windsurf.

Imagine you download what looks like a normal software project, open the folder on your laptop, and before you've read a single line of code an invisible script reaches into your machine and copies the passwords to your employer's entire cloud account. That is exactly what CVE-2026-12957 enabled.

The affected product is Amazon Q Developer, an AI-powered coding assistant built into the popular code editor Visual Studio Code that watches a programmer write code and suggests improvements in real time. Millions of professional developers use it daily.

How did the hackers get in?

The entry point was an MCP server, short for Model Context Protocol server, essentially a plug-in that lets AI tools connect to other business systems. Amazon Q automatically ran instructions from these plug-ins the moment a developer opened a project folder, with no approval click required.

A criminal could create a poisoned project folder, disguised as a useful open-source library, a job-interview coding test, or a compromised dependency, and slip malicious MCP instructions inside it. The moment a developer opened that folder with Amazon Q active, the instructions ran silently.

Because Amazon Q also inherited all of the developer's active login sessions, those invisible instructions had immediate access to AWS credentials, API keys, and SSH agent sockets. Wiz confirmed this by running a test command, "aws sts get-caller-identity", that successfully captured a live AWS session.

Code review, the standard professional practice of reading through a project before trusting it, offers zero protection. The malicious payload fires before any human eyes touch the source code, because execution happens at the moment the extension initialises.

Wiz disclosed the flaw to AWS, which was first reported by Dark Reading, and AWS shipped a fix in Language Server version 1.65.0. If you're already on that version or higher, no further action is needed.

Should you worry even after patching?

Patching one product doesn't close the underlying problem. As Wiz researcher Maor Dokhanian told Dark Reading, nearly identical flaws have been found in Claude Code (CVE-2025-59536), Cursor (CVE-2025-54136), and Windsurf (CVE-2026-30615). The pattern is consistent: AI tools that trust project files a little too automatically, built on an architecture that wasn't designed with supply-chain attacks in mind. Dokhanian noted to Dark Reading that these issues exist at the architectural level in both large language models and MCP itself, which means a patch doesn't retire the threat class.

We reported this flaw on 26 June 2026, and the broader supply-chain context is worth reading alongside our May piece on TrapDoor, a cross-registry campaign that was already targeting AI coding assistant files specifically.

For anyone outside a dev team, the risk is indirect but concrete. Stolen developer credentials reach customer databases and can quietly tamper with software that millions of end users download.

Developers should treat any "Untrusted MCP Server" warning from any AI coding tool as a hard stop. Be suspicious of repositories that arrive through unsolicited contact or unfamiliar pull requests. Audit every MCP server configuration in your environment.

The post-mortem on this class of attack will keep saying the same thing: the credentials were already there, inherited and waiting for the first process that asked.

© 2026 Threat Vectr