How We Impersonated Cloud Code by Google Cloud and Took Over GCP Accounts - Upwind | Cloud Security Happens at Runtime
The Upwind security research team is constantly examining threat landscapes and potential attack paths. In one of our recent searches, we discovered an anomaly in the authentication behavior of Google Developer tools that security practitioners should be aware of. We discovered this threat landscape by running scans on GCP Cloud Code, during which we found exposed OAuth client IDs and secrets, along with the source code for a VS Code extension included as a CSV file. To check this further, we crafted and tested a malicious VS Code extension, which allowed us to successfully extract user tokens and transfer them to remote buckets. Once we discovered that this threat landscape existed, we quickly compiled an advisory and submitted it to Google. However, much to our surprise, our submission did not meet their bug bounty policy criteria, and we received a response from Google explaining that this functionality was intentionally designed. Google’s response was as follows: “Client-side devel
How We Impersonated Cloud Code by Google Cloud and Took Over GCP Accounts - Upwind Skip to main content Skip to footer Home > Feed > How We Impersonated Cloud Code by Google Cloud and Took Over GCP Accounts Research How We Impersonated Cloud Code by Google Cloud and Took Over GCP Accounts Warning : Undefined variable $photo in /nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code on line 24 Warning : Trying to access array offset on value of type null in /nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval(
Explore this link on the map →related reading
- Compromised Cloud Compute Credentials: Case Studies From the Wildunit42.paloaltonetworks.com
- Security incident disclosure — July 2026huggingface.co
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- A Guide to Claude Code 2.0 and getting better at using coding agents – sankalp's blogsankalp.bearblog.dev
- The Claude Code Source Leak: fake tools, frustration regexes, undercover mode, and more | Alex Kim's blogalex000kim.com
- Best practices for Claude Code - Claude Code Docsanthropic.com
- How we contain Claude across products \ Anthropicanthropic.com
- AI and Cloud Computing Services | Google Cloudcloud.google.com
- State of Cloud Security | Datadogdatadoghq.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- API Keys, API Keys everywhereblog.kchung.co
- Secure AI Agent & User Authentication | Auth0auth0.com