How We Impersonated Cloud Code by Google Cloud and Took Over GCP Accounts

Moshiko

BSides NYC 2024 · Day 1 · Tech - Red

This talk, presented by Moshiko from Appwin at BSides NYC, unveils critical security research demonstrating how his team successfully impersonated Google Cloud Code, a popular Visual Studio Code extension, to gain full administrative access to Google Cloud Platform (GCP) accounts. The research highlights profound security risks inherent in the rapid adoption of **DevOps tools**, **hybrid cloud** environments, and the often-overlooked vulnerabilities within **VS Code extensions** and their underlying development practices.

AI review

Solid bug-hunting work that found a genuine hardcoded OAuth client secret in a widely-deployed Google extension and built a convincing PoC around it. The vulnerability is real and the attack chain is coherent, but the underlying class of bug — hardcoded secrets in client-side JS — is decades old, and the talk doesn't push the technique anywhere new. Vendor product placement is visible throughout, which dilutes the research signal.

Watch on YouTube