543,000 Exposed GitHub Credentials Found in Public Repositories
Over 543,000 active credentials were discovered in public GitHub repositories during a July 2026 analysis, revealing persistent vulnerabilities in code-sharing platforms.
Key Findings of the Study
The research, conducted by a cybersecurity firm, examined 224 million repositories and 58 billion files, identifying 543,699 unique credentials distributed across 1.1 million files and forks. Approximately 10% of these working credentials dated back more than 6.3 years, with the oldest still-valid entry originating from 2009.
Scope of the Study
The dataset used for analysis was compiled from a large-scale crawl concluding on August 7, 2025, with validation performed in July 2026. The study highlighted that exposed credentials can remain functional for extended periods if not revoked, emphasizing the long-term risks of insecure data exposure.
Comparison with Other Platforms
The research revealed that GitHub’s credential exposure problem exceeds that of other platforms. A prior assessment of Hugging Face repositories found 221,303 active credentials, significantly lower than GitHub’s 543,699. The density of exposed secrets increased over time, with working credentials per million files rising from 3.72 in 2015 to 11.62 in 2025.
Implications for Developers
This trend underscores growing challenges for developers in mitigating risks associated with public code repositories. The study emphasizes the urgency of rotating credentials immediately upon exposure and advises security teams to audit repository histories, remove sensitive data from old commits, and implement automatic expiration for active secrets.
Push Protection Analysis
GitHub’s Push Protection feature, introduced in 2022 for Advanced Security users and later enabled by default in 2023, aims to block secret exposure during code pushes. However, the study found that 36.8% of the 543,699 credentials identified in July 2026 were exposed after Push Protection became active.
Coverage Gaps
Additionally, 51.8% of the credentials fell into categories not covered by the default protection, such as database connection strings and Google API keys. While the feature reduced exposure rates for protected categories by 53% post-activation, gaps in coverage remain.
Credential Validity by Service
The validity of credentials varied by service. Of 101,886 exposed npm tokens, only one remained active, whereas 69,041 of 126,963 Google Cloud service account credentials were still valid. These disparities highlight the need for tailored security measures based on the type of credential.
Risk of Public Exposure
The presence of hundreds of thousands of valid credentials in public repositories poses a significant risk, particularly when they grant access to cloud services, databases, or APIs. Publicly exposed credentials should be treated as compromised, with immediate revocation or rotation and thorough review of connected systems for unauthorized access.
The study did not confirm whether attackers exploited the exposed data, but the sheer volume of active credentials creates a critical security threat.
Conclusion
Developers and organizations must prioritize proactive measures to prevent long-term vulnerabilities in shared code environments. The findings stress the urgency of rotating credentials immediately upon exposure and implementing robust security practices to mitigate risks associated with public code repositories.
