AWS issued a post and they talk about revoking and replacing a credential.
So maybe the hacker was able to directly push?
https://aws.amazon.com/security/security-bulletins/AWS-2025-...
So maybe the hacker was able to directly push?
https://aws.amazon.com/security/security-bulletins/AWS-2025-...