Over 543,000 valid credentials exposed in public GitHub repositories

A staggering number of valid login credentials has been exposed in public GitHub repositories, leaving countless users vulnerable to unauthorized access and potential identity theft. A recent investigation by cybersecurity researchers uncovered over 543,000 compromised user credentials, which were found to be still active in July despite GitHub’s attempts to mitigate such leaks.

The alarming discovery was made after the researchers scanned thousands of public GitHub repositories for sensitive data, including login credentials, API keys, and database passwords. These repositories are meant to be publicly accessible, but they often contain code snippets, configuration files, or other pieces of information that can inadvertently expose sensitive data. In this case, the researchers found a large number of valid usernames and passwords, many of which were paired with email addresses, making it even easier for attackers to use them for malicious purposes.

The exposed credentials appear to have originated from various sources, including GitHub users themselves, third-party integrations, or other services that utilize the platform. It’s worth noting that some of these credentials may have been intentionally shared within a project or repository as part of legitimate collaboration efforts, while others might be the result of carelessness or accidental exposure.

The discovery highlights the ongoing challenge of balancing public sharing and security on platforms like GitHub. While open-source projects rely heavily on public repositories to facilitate collaboration and innovation, the ease with which sensitive data can be exposed poses a significant risk to users’ online security. Furthermore, attackers often scan public repositories for vulnerable code or misconfigured integrations, making these findings an attractive target.

The sheer scale of this leak raises concerns about the long-term implications for user security. Attackers can use these credentials to gain unauthorized access to targeted accounts, which may lead to phishing scams, identity theft, or even the exploitation of sensitive data stored within those accounts. In light of this discovery, it’s essential for GitHub users to exercise extreme caution when sharing code and other sensitive information publicly.

As a practical takeaway, users should be vigilant about reviewing their own repository settings and ensuring that sensitive data is not exposed inadvertently. This includes being mindful of what information is shared in configuration files or code snippets, regularly reviewing access permissions, and taking advantage of GitHub’s security features to protect against accidental leaks. By being proactive about security, individuals can minimize the risk of exposure and safeguard their online presence.


Source: Bleeping Computer — 2026-09-30