So maybe the hacker was able to directly push?
https://aws.amazon.com/security/security-bulletins/AWS-2025-...