Over 543,000 valid credentials exposed in public GitHub repositories

Over 543,000 valid credentials exposed in public GitHub repositories have been left vulnerable despite the platform’s security measures. Truffle Security conducted a comprehensive scan of 224 million repositories and 58 billion files, revealing that more than half a million unique credentials were publicly accessible for an average of nearly two years.

The researchers found that approximately 10% of working credentials dated back to 2009 or earlier, with the oldest one discovered in 2009. The majority of these exposed credentials, over 543,699, appeared repeatedly across multiple files and repositories, including forks. This staggering number is more than double what Truffle Security reported on Hugging Face last year.

GitHub’s Push Protection mechanism was designed to prevent accidental leaks of sensitive data by scanning incoming code for secret patterns like API keys and access tokens. However, the feature does not revoke previously exposed credentials, which has left many users vulnerable. In fact, nearly 36% of the exposed credentials were leaked after Push Protection became available in February 2024.

One of the most concerning aspects of this discovery is that a significant portion of live credentials fall into categories that GitHub’s default Push Protection does not block. These include database connection strings and Google API keys, which are often used to access sensitive data. However, Truffle Security reports that within its coverage, the rate of exposed credentials in protected categories fell by 53% after the feature was enabled by default.

A closer look at the dataset reveals some surprising patterns in credential revocation rates. For example, while over 99% of committed npm tokens were no longer valid, a significant number of Google Cloud service account credentials remained active and working. This highlights the need for users to regularly review and rotate their exposed secrets to prevent unauthorized access.

The practical takeaway from this research is that users must take immediate action to protect themselves. This includes rotating exposed credentials, cleaning up repositories, scanning history, and setting automatic expiration for all active secrets. While Truffle Security’s findings do not reveal the percentage of stolen and abused credentials, they serve as a stark reminder of the importance of staying vigilant in the face of ever-evolving threats.

In an era where AI-powered attacks are becoming increasingly common, it is more crucial than ever to prioritize security best practices. By understanding the scale and scope of credential exposure on GitHub, users can take proactive steps to prevent data breaches and protect their sensitive information. As the cybersecurity landscape continues to evolve, one thing remains clear: vigilance and responsible behavior are essential for staying ahead of threats.


Source: Bleeping Computer — 2026-09-30