GitHub Repositories Leaked Over 543,000 Valid Credentials
More than 543,000 valid credentials exposed on GitHub remained usable when security researchers analyzed millions of public repositories, highlighting the continuing risk of developers accidentally publishing secrets.
Truffle Security identified 543,699 unique valid credentials across more than 1.1 million files and repositories, including copies stored in forks.
Researchers scanned 224 million repositories and more than 58 billion files during the analysis. The median exposed credential remained publicly accessible for 784 days, while around 10% of working credentials were more than 6.3 years old.
GitHub credential exposure continues to increase
Truffle Security found that the density of working credentials increased significantly over the past decade.
The rate climbed from 3.72 working credentials per million files in 2015 to 11.62 per million files in 2025.
GitHub also contained more than twice as many exposed working credentials as researchers previously discovered on Hugging Face, where Truffle Security identified 221,303.
The findings show that valid secrets remain common in public repositories despite protections designed to prevent developers from accidentally publishing credentials.
GitHub Push Protection blocked many supported secrets
GitHub’s Push Protection scans incoming code for supported secrets, including API keys and access tokens, and can block developers from committing them.
However, researchers identified 199,843 valid credentials exposed after GitHub enabled Push Protection for all users in February 2024. These credentials accounted for about 36.8% of the total discovered during the analysis.
Around 51.8% of valid credentials belonged to categories that GitHub’s default Push Protection does not block, including database connection strings and Google API keys.
For credential types that Push Protection does cover, researchers found that the exposure rate dropped by 53% after GitHub enabled the feature by default.
The results suggest that Push Protection significantly reduces leaks for supported secrets, but many credential types remain outside its default coverage.
Organizations should rotate exposed credentials immediately
Organizations should immediately rotate any credential that has appeared in a public repository because removing the secret from the current version of the code does not guarantee that attackers can no longer access it.
Teams should also clean affected repositories and inspect repository history for credentials committed in earlier versions.
Truffle Security also recommends configuring automatic expiration for active credentials, which can reduce the useful lifetime of credentials that developers accidentally expose.
GitHub has faced other security issues recently. GitHub Actions were re-enabled while Mini Shai-Hulud malware remained active, while fake LastPass GitHub repositories pushed Rapuncel malware to Windows users.
Elsewhere, Microsoft recently warned about a critical Zimbra command injection flaw that attackers are actively exploiting.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages