Find notable cyber news and cases, enriched with sources, timelines, and signals.

N8n API tokens exposed in public GitHub commits

Data Leak
First reported
Last updated
Happening score
H score 58
1 unique sources, 1 articles

Summary

Hide ▲

n8n API tokens exposed in public GitHub commits remained valid on 321 reachable instances, giving authenticated access that could expose workflows, stored credentials, and sensitive execution data. The exposure turned a committed secret into a live access path without any software vulnerability being exploited. Researchers also measured 4,576 unique credentials tied to 1,255 hostnames, showing how widely the leaked tokens spread.

Related Happenings

Megalodon GitHub CI/CD supply-chain campaign

Campaign
H score50 First: 22.05.2026 14:55 Last: 22.05.2026 14:55 Sources 1

About this happening: The Megalodon campaign pushed 5,718 malicious commits into 5,561 GitHub repositories in about six hours, creating a broad CI/CD secret-theft risk across develo...

GitHub internal repositories private-code leak claim

Data Leak
H score46 First: 20.05.2026 08:08 Last: 20.05.2026 08:08 Sources 1

About this happening: GitHub is facing a claimed leak of internal repositories after TeamPCP said it had access to about 4,000 private-code repos and tried to sell samples. The alleged expo...

Latest development: 21.05.2026 17:45

A malicious version of Nx Console 18.95.0 was uploaded to Visual Studio Marketplace and Open VSX on May 18, fetched an obfuscated payload, and harvested secrets from ~/.vault-token, /etc/vault/token, .npmrc, ghp_/gho_/ghs_ tokens, AWS metadata, and other local sources; GitHub said the poisoned VS Code extension led to unauthorized access to about 3800 internal repositories.

Rwl.angular-console (Nx Console) hit by network compromise

Incident
H score41 First: 19.05.2026 10:49 Last: 19.05.2026 10:49 Sources 1

About this happening: The Nx Console extension rwl.angular-console 18.95.0 was compromised on the VS Code Marketplace, exposing developers to a credential-stealing payload and suppl...

Widespread exposure and misconfiguration in self-hosted AI infrastructure

Trend
H score76 First: 05.05.2026 13:30 Last: 05.05.2026 13:30 Sources 1

About this happening: A large-scale measurement found self-hosted AI infrastructure was being deployed with widespread exposure and no authentication, creating a broad risk of data theft, workf...

Moltbook wide-open database exposure

Data Leak
H score52 First: 22.04.2026 13:41 Last: 22.04.2026 13:41 Sources 1

About this happening: The Moltbook database exposure placed 35,000 email addresses and 1.5 million agent API tokens at risk, creating immediate potential for account hijacking and credentia...

Timeline

  1. 05.08.2026 13:35 2 articles · 2h ago

    GitGuardian finds leaked n8n API tokens still accepted by reachable instances

    Initial Disclosure

    GitGuardian researchers identified n8n API tokens exposed in public GitHub commits and verified that 321 reachable n8n instances still accepted at least one leaked token. The research tied 4,576 unique credentials to 1,255 hostnames and showed that authenticated access could expose workflow definitions, execution data, stored credentials, and downstream secrets without exploiting a software vulnerability.

    Show sources