N8n API tokens exposed in public GitHub commits
Data Leak
Summary
Hide ▲
Show ▼
n8n API tokens exposed in public GitHub commits remained valid on 321 reachable instances, giving authenticated access that could expose workflows, stored credentials, and sensitive execution data. The exposure turned a committed secret into a live access path without any software vulnerability being exploited. Researchers also measured 4,576 unique credentials tied to 1,255 hostnames, showing how widely the leaked tokens spread.
Related Happenings
Megalodon GitHub CI/CD supply-chain campaign
Campaign
H score50
First: 22.05.2026 14:55
Last: 22.05.2026 14:55
Sources 1
About this happening:
The Megalodon campaign pushed 5,718 malicious commits into 5,561 GitHub repositories in about six hours, creating a broad CI/CD secret-theft risk across develo...
Megalodon GitHub CI/CD supply-chain campaign
CampaignAbout this happening: The Megalodon campaign pushed 5,718 malicious commits into 5,561 GitHub repositories in about six hours, creating a broad CI/CD secret-theft risk across develo...
GitHub internal repositories private-code leak claim
Data Leak
H score46
First: 20.05.2026 08:08
Last: 20.05.2026 08:08
Sources 1
About this happening:
GitHub is facing a claimed leak of internal repositories after TeamPCP said it had access to about 4,000 private-code repos and tried to sell samples. The alleged expo...
GitHub internal repositories private-code leak claim
Data LeakAbout this happening: GitHub is facing a claimed leak of internal repositories after TeamPCP said it had access to about 4,000 private-code repos and tried to sell samples. The alleged expo...
Latest development: 21.05.2026 17:45
A malicious version of Nx Console 18.95.0 was uploaded to Visual Studio Marketplace and Open VSX on May 18, fetched an obfuscated payload, and harvested secrets from ~/.vault-token, /etc/vault/token, .npmrc, ghp_/gho_/ghs_ tokens, AWS metadata, and other local sources; GitHub said the poisoned VS Code extension led to unauthorized access to about 3800 internal repositories.
Rwl.angular-console (Nx Console) hit by network compromise
Incident
H score41
First: 19.05.2026 10:49
Last: 19.05.2026 10:49
Sources 1
About this happening:
The Nx Console extension rwl.angular-console 18.95.0 was compromised on the VS Code Marketplace, exposing developers to a credential-stealing payload and suppl...
Rwl.angular-console (Nx Console) hit by network compromise
IncidentAbout this happening: The Nx Console extension rwl.angular-console 18.95.0 was compromised on the VS Code Marketplace, exposing developers to a credential-stealing payload and suppl...
Widespread exposure and misconfiguration in self-hosted AI infrastructure
Trend
H score76
First: 05.05.2026 13:30
Last: 05.05.2026 13:30
Sources 1
About this happening:
A large-scale measurement found self-hosted AI infrastructure was being deployed with widespread exposure and no authentication, creating a broad risk of data theft, workf...
Widespread exposure and misconfiguration in self-hosted AI infrastructure
TrendAbout this happening: A large-scale measurement found self-hosted AI infrastructure was being deployed with widespread exposure and no authentication, creating a broad risk of data theft, workf...
Moltbook wide-open database exposure
Data Leak
H score52
First: 22.04.2026 13:41
Last: 22.04.2026 13:41
Sources 1
About this happening:
The Moltbook database exposure placed 35,000 email addresses and 1.5 million agent API tokens at risk, creating immediate potential for account hijacking and credentia...
Moltbook wide-open database exposure
Data LeakAbout this happening: The Moltbook database exposure placed 35,000 email addresses and 1.5 million agent API tokens at risk, creating immediate potential for account hijacking and credentia...
Timeline
-
05.08.2026 13:35 2 articles · 2h ago
GitGuardian finds leaked n8n API tokens still accepted by reachable instances
Initial DisclosureGitGuardian researchers identified n8n API tokens exposed in public GitHub commits and verified that 321 reachable n8n instances still accepted at least one leaked token. The research tied 4,576 unique credentials to 1,255 hostnames and showed that authenticated access could expose workflow definitions, execution data, stored credentials, and downstream secrets without exploiting a software vulnerability.
Show sources
- Leaked n8n API Tokens Exposed Live Instances to Credential Theft — thehackernews.com — 05.08.2026 13:35
- Leaked n8n API Tokens Exposed Live Instances to Credential Theft — thehackernews.com — 05.08.2026 13:35