ALEXKRI.NET
Resume Contact
← Back

The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub

Your private repos are a credential store whether you meant them to be. One compromised GitHub token cloned 18 private repositories; hardcoded AWS keys sitting inside them got the attacker into a second AWS account, then SSM SendCommand on a production domain controller and Python export scripts staged in S3. The tell wasn’t the token - it was the user agent flipping from TeamCity and aws-sdk-go to aws-cli on Kali Linux.

Read the source ↗