Over Half a Million Active Credentials Found in Public GitHub Repositories
Researchers from Truffle Security uncovered 543,699 unique, still-valid credentials in public GitHub code during an analysis conducted on July 27–28, 2026, exposing systemic failures in secret management. The findings, derived from The Stack v3 a massive public-code dataset containing 224.5 million repositories and 58.5 billion files (crawled by August 7, 2025) reveal that credentials often remain usable for years after exposure, despite GitHub’s security controls.
The median exposed credential had lingered in a public default branch for 784 days, with 10% active for at least 6.3 years. The oldest was a database credential in an Erlang server configuration, last modified in June 2009, which still authenticated 16.1 years later. Due to limitations in the dataset (which only captures default branches and file modification times), the true scale of exposure is likely larger.
While GitHub introduced free secret-scanning alerts for public repositories in February 2023 and default push protection for free users in February 2024, the research found that 36.8% of active credentials (199,843) were exposed after push protection was enabled. Another 245,959 predated free alerts, and 97,897 appeared during the gap between the two features. Push protection reduced exposure density for covered credential types by 53%, compared to just 7% for unprotected types highlighting its partial effectiveness.
However, 51.8% of live credentials used formats not blocked by default push protection, including:
- 69,041 Google Cloud service-account credentials
- 51,067 MongoDB connection strings
- 33,343 Google API keys
- 31,374 live Gemini keys (sharing the AIzaSy prefix with other Google services, complicating detection)
Provider revocation policies played a critical role in mitigating risk. While only 1 of 101,886 npm tokens, 260 of 73,048 GitHub tokens, and 15 of 30,437 Hugging Face tokens remained active thanks to automated revocation 11,465 of 12,985 PostgreSQL strings, 1,806 of 2,421 MySQL strings, and 69,041 of 126,963 Google Cloud credentials still worked, underscoring the need for immediate rotation.
The research emphasizes that deleting exposed credentials is insufficient, as attackers may have already harvested copies. Organizations must revoke or rotate credentials first, then clean repositories, while also scanning full Git histories, enforcing strict bypass controls, and adopting short-lived credentials. While push protection reduces new leaks, only automated revocation and expiration can fully neutralize existing exposures.
Source: https://cybersecuritynews.com/543699-unique-credentials-exposed/
MongoDB TPRM report: https://www.rankiteo.com/company/mongodbinc
GitHub TPRM report: https://www.rankiteo.com/company/github
MySQL TPRM report: https://www.rankiteo.com/company/percona
npm TPRM report: https://www.rankiteo.com/company/npm-inc-
"id": "npmmonpergit1790850671",
"linkid": "npm-inc-, mongodbinc, percona, github",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Various',
'location': 'Global',
'name': 'Multiple organizations',
'size': 'Various',
'type': 'Various'}],
'attack_vector': 'Publicly accessible code repositories',
'data_breach': {'file_types_exposed': 'Code files (e.g., configuration files, '
'scripts)',
'number_of_records_exposed': '543,699',
'personally_identifiable_information': 'Potentially included '
'in exposed '
'credentials',
'sensitivity_of_data': 'High (credentials, PII, and system '
'access)',
'type_of_data_compromised': 'Credentials, API keys, database '
'connection strings, '
'service-account credentials'},
'date_detected': '2026-07-27',
'description': 'Researchers from Truffle Security uncovered 543,699 unique, '
'still-valid credentials in public GitHub code during an '
'analysis conducted on July 27–28, 2026, exposing systemic '
'failures in secret management. The findings reveal that '
'credentials often remain usable for years after exposure, '
'despite GitHub’s security controls.',
'impact': {'brand_reputation_impact': 'Negative impact on organizations with '
'exposed credentials',
'data_compromised': '543,699 unique, still-valid credentials',
'identity_theft_risk': 'High risk due to exposed credentials',
'legal_liabilities': 'Potential regulatory violations due to '
'exposed sensitive data',
'operational_impact': 'Potential unauthorized access to systems '
'and data',
'systems_affected': 'Public GitHub repositories'},
'investigation_status': 'Completed (research findings published)',
'lessons_learned': 'Deleting exposed credentials is insufficient; '
'organizations must revoke or rotate credentials first, '
'scan full Git histories, enforce strict bypass controls, '
'and adopt short-lived credentials. Push protection '
'reduces new leaks, but only automated revocation and '
'expiration can fully neutralize existing exposures.',
'post_incident_analysis': {'corrective_actions': ['Immediate credential '
'revocation and rotation',
'Repository cleanup',
'Adoption of short-lived '
'credentials',
'Enhanced monitoring and '
'scanning of Git histories'],
'root_causes': ['Inadequate secret management '
'practices',
'Delayed credential revocation',
"Gaps in GitHub's secret-scanning "
'and push protection features',
'Use of credential formats not '
'blocked by default push '
'protection']},
'recommendations': ['Revoke or rotate exposed credentials immediately',
'Clean repositories after revocation',
'Scan full Git histories for exposed secrets',
'Enforce strict bypass controls for push protection',
'Adopt short-lived credentials'],
'references': [{'source': 'Truffle Security Research'},
{'source': 'The Stack v3 Dataset'}],
'regulatory_compliance': {'regulations_violated': 'Potential violations of '
'data protection '
'regulations (e.g., GDPR, '
'CCPA)'},
'response': {'enhanced_monitoring': 'GitHub secret-scanning alerts and push '
'protection',
'remediation_measures': 'Credential revocation, repository '
'cleanup, and adoption of short-lived '
'credentials',
'third_party_assistance': 'Truffle Security'},
'title': 'Over Half a Million Active Credentials Found in Public GitHub '
'Repositories',
'type': 'Data Exposure',
'vulnerability_exploited': 'Inadequate secret management and delayed '
'credential revocation'}