AWS best practices is to use AWS SSO, which accomplishes this same effect but without any long-lived local credentials. It works really well.
aws-vault is one of them, though out of support now, aws-okta [1] is another.
Just an FYI it's no longer supported and it looks like the fork has gone stagnant, too.