I don't think they are inspecting the app ; they don't need to. They can see that there are a higher-than-average number of API accesses from a given platform, using the AWS Secret Key as the login credential.
Also, Amazon would use Aho-Corasick if they were really in the mood for violating the Google Play TOS.
It's more likely that they have an alert when the secret key is used to access an account from many different IP addresses, and looking at the user-agent string in the HTTP headers probably pointed them towards an Android app.
It wouldn't be too hard for them to then look to see who owns the AWS account and then search for that person's name in the Android app store.