MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-30 · via BleepingComputer

Half-Million Active Login Credentials Found Lingering in Public Code Repositories

Image via BleepingComputer
Image via BleepingComputer

A security research firm scanning 224 million GitHub repositories discovered over 543,000 still-active credentials that had been publicly exposed, with the median exposure period lasting nearly two and a half years. Despite GitHub's Push Protection feature reducing credential leaks in protected categories by 53 percent since its mandatory rollout in February 2024, roughly 37 percent of exposed credentials were leaked after the safeguard became default. The research reveals that more than half of working credentials fall into categories not blocked by GitHub's current security measures.

Expanded Detail

Truffle Security's comprehensive analysis of GitHub repositories uncovered a troubling pattern: credentials remained exposed for extended periods despite platform protections. The research tracked 543,699 unique credentials across millions of files, with some dating back nearly two decades. Secret density has grown substantially over time, increasing more than threefold since 2015, suggesting that credential leaks are becoming a larger problem as codebases expand. The findings reveal significant variations in how different services handle exposed credentials—npm tokens show high revocation rates while Google Cloud service accounts demonstrate concerning persistence in the wild.

GitHub's Push Protection feature has demonstrated measurable effectiveness within its scope, reducing exposed credentials in protected categories by more than half since becoming mandatory in early 2024. However, a critical gap remains: over half of working credentials belong to categories the tool doesn't currently monitor, including database connection strings and certain API key types. This limitation means the platform's default safeguard, while helpful, leaves substantial blind spots in credential protection.

Context

The discovery could have significant implications for organizational security posture. Development teams and their employers may face elevated risk if exposed credentials remain undetected and unrevoked in repositories. The findings suggest that automatic secret rotation and proactive scanning are increasingly necessary security practices. However, the research doesn't clarify how many exposed credentials are actually exploited versus merely present, making it difficult to assess the true scope of active threats from this exposure vector.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
AI Code Assistants Inadvertently Exposed Thousands of Sensitive Corporate Images Through Public GitHub Repositories · Artificial intelligence
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Over 543,000 valid credentials exposed in public GitHub repositories.” Browse more stories.