Skip to content
>_ITDITDWeb Security Platform
tag

GitHub

2 articles with this tag

2026-10-04

543,699 credentials published on GitHub still worked (2026 study): why you must revoke, not delete, and what developers should do

A security company that sells secret-scanning tools examined a snapshot of about 224 million public repositories collected for LLM training and reported that 543,699 credentials still authenticated in late July 2026. The median time since exposure was 784 days. Almost all npm and GitHub tokens had been invalidated, while 75-88% of database connection strings still worked. More than 199,000 of the live credentials appeared after GitHub turned push protection on by default, and over half of the live ones were types push protection does not block by default. This site's conclusion: a credential pushed to a public repository cannot be recalled by deleting the file or rewriting history, so revoke it first. Whether a leaked credential is revoked automatically depends on the issuer; connection strings and many API keys stay valid until you stop them.

2026-08-22

npm Supply-Chain Worms: How Credentials Are Stolen at Install Time, and How to Defend

Adding a dependency means running someone else's code with your privileges, so the defense belongs at install time. This site's view: signatures and provenance did not stop this campaign, so they cannot be the basis of trust. What works is disabling install scripts by default, letting dependencies age a few days before adopting them, and keeping tokens short-lived and narrowly scoped. And if you suspect infection, the order in which you revoke matters.