Half-Million Active Login Credentials Found Lingering in Public Code Repositories

A security research firm scanning 224 million GitHub repositories discovered over 543,000 still-active credentials that had been publicly exposed, with the median exposure period lasting nearly two and a half years. Despite GitHub's Push Protection feature reducing credential leaks in protected categories by 53 percent since its mandatory rollout in February 2024, roughly 37 percent of exposed credentials were leaked after the safeguard became default. The research reveals that more than half of working credentials fall into categories not blocked by GitHub's current security measures.
Truffle Security's comprehensive analysis of GitHub repositories uncovered a troubling pattern: credentials remained exposed for extended periods despite platform protections. The research tracked 543,699 unique credentials across millions of files, with some dating back nearly two decades. Secret density has grown substantially over time, increasing more than threefold since 2015, suggesting that credential leaks are becoming a larger problem as codebases expand. The findings reveal significant variations in how different services handle exposed credentials—npm tokens show high revocation rates while Google Cloud service accounts demonstrate concerning persistence in the wild.
GitHub's Push Protection feature has demonstrated measurable effectiveness within its scope, reducing exposed credentials in protected categories by more than half since becoming mandatory in early 2024. However, a critical gap remains: over half of working credentials belong to categories the tool doesn't currently monitor, including database connection strings and certain API key types. This limitation means the platform's default safeguard, while helpful, leaves substantial blind spots in credential protection.
The discovery could have significant implications for organizational security posture. Development teams and their employers may face elevated risk if exposed credentials remain undetected and unrevoked in repositories. The findings suggest that automatic secret rotation and proactive scanning are increasingly necessary security practices. However, the research doesn't clarify how many exposed credentials are actually exploited versus merely present, making it difficult to assess the true scope of active threats from this exposure vector.