Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

More Than 543,000 Valid Credentials Found in Public GitHub Repositories

Truffle Security found 543,699 unique credentials that were still valid in July in public GitHub repositories, according to research reported by BleepingComputer. The credentials appeared repeatedly across more than 1.1 million files and repositories, including forks.

The analysis scanned 224 million repositories and more than 58 billion files. A unique credential remained publicly accessible for a median of 784 days. About 10% of working credentials were more than 6.3 years old, and the oldest dated to 2009. The dataset was assembled to train large language models from a crawl that ended on August 7, 2025.

Truffle Security counted 199,843 credentials exposed after GitHub activated Push Protection for all users in February 2024, or about 36.8% of the total. More than half, 51.8%, belonged to categories that the default protection does not block, including database connection strings and Google API keys. Within categories it does cover, the rate of exposed credentials fell 53% after the feature became enabled by default.

The findings also varied by credential type. Of 101,886 committed npm tokens, only 1 still worked. Of 126,963 exposed Google Cloud service account credentials, 69,041 were still valid. The research does not show what share of the exposed credentials were stolen or misused.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.