MCP Auto Execution From Git Clone to Cloud Compromise
Amazon Q in VS Code pulled config files from cloned repos and ran MCP servers automatically.
Attackers planted a malicious MCP server config in a public repo. After a developer opened the cloned folder in VS Code and activated Amazon Q, the vulnerable extension could auto-load the malicious MCP config and run it with access to credentials loaded in the developer environment.
Users on vulnerable Amazon Q Developer versions were exposed if they opened an untrusted workspace containing a malicious MCP config before the AWS fix.
Wiz researchers demonstrated the full chain in under 30 seconds from clone to credential access.
