GitHub App private keys leaked in public code
Data Leak
Summary
Hide ▲
Show ▼
GitHub App private keys leaked in public code remained valid for GitHub's API, leaving some exposed credentials able to reach private repositories and organization controls. The research found that 474 leaked keys still authenticated as 440 distinct Apps, and some grants included organization administration and workflow control. Because these keys do not expire until manually deleted, the exposure created an ongoing access risk rather than a one-time leak.
Related Happenings
CISA recommends continuous secrets scanning and stronger key management after GitHub leak
Defensive Guidance
H score26
First: 13.07.2026 18:03
Last: 13.07.2026 18:03
Sources 1
About this happening:
CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...
CISA recommends continuous secrets scanning and stronger key management after GitHub leak
Defensive GuidanceAbout this happening: CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...
GitHub Agentic Workflows indirect prompt injection security flaw
Vulnerability
H score27
First: 07.07.2026 17:04
Last: 07.07.2026 17:04
Sources 1
About this happening:
GitHub Agentic Workflows has an indirect prompt injection flaw that can let a public issue leak content from private repositories into public comments. The risk is...
GitHub Agentic Workflows indirect prompt injection security flaw
VulnerabilityAbout this happening: GitHub Agentic Workflows has an indirect prompt injection flaw that can let a public issue leak content from private repositories into public comments. The risk is...
Visual Studio Code VS Code token-theft zero-day security flaw
Vulnerability
H score44
First: 03.06.2026 09:50
Last: 03.06.2026 09:50
Sources 1
About this happening:
A Visual Studio Code (VS Code) zero-day lets attackers steal GitHub OAuth tokens by abusing the editor's sandboxed webview message-passing system. The flaw is especial...
Visual Studio Code VS Code token-theft zero-day security flaw
VulnerabilityAbout this happening: A Visual Studio Code (VS Code) zero-day lets attackers steal GitHub OAuth tokens by abusing the editor's sandboxed webview message-passing system. The flaw is especial...
Latest development: 03.06.2026 15:58
Microsoft has acknowledged a Visual Studio Code vulnerability that can let an attacker use a crafted link and malicious webview message-passing to steal a victim's GitHub OAuth token via GitHub.dev, and said it is working on a fix; Microsoft also said the issue does not affect VS Code Desktop.
Megalodon GitHub CI/CD supply-chain campaign
Campaign
H score50
First: 22.05.2026 14:55
Last: 22.05.2026 14:55
Sources 1
About this happening:
The Megalodon campaign pushed 5,718 malicious commits into 5,561 GitHub repositories in about six hours, creating a broad CI/CD secret-theft risk across develo...
Megalodon GitHub CI/CD supply-chain campaign
CampaignAbout this happening: The Megalodon campaign pushed 5,718 malicious commits into 5,561 GitHub repositories in about six hours, creating a broad CI/CD secret-theft risk across develo...
Rwl.angular-console (Nx Console) hit by network compromise
Incident
H score41
First: 19.05.2026 10:49
Last: 19.05.2026 10:49
Sources 1
About this happening:
The Nx Console extension rwl.angular-console 18.95.0 was compromised on the VS Code Marketplace, exposing developers to a credential-stealing payload and suppl...
Rwl.angular-console (Nx Console) hit by network compromise
IncidentAbout this happening: The Nx Console extension rwl.angular-console 18.95.0 was compromised on the VS Code Marketplace, exposing developers to a credential-stealing payload and suppl...
Timeline
-
23.09.2026 18:00 2 articles · 1d ago
GitHub App private keys leaked in public code
Initial DisclosureGitGuardian identified GitHub App private keys in public code that still authenticated to GitHub's API. The first pass showed that some leaked keys could read private repositories, administer organizations, and control workflows.
Show sources
- Hundreds of Leaked GitHub App Keys Still Authenticate — www.infosecurity-magazine.com — 23.09.2026 18:00
- Hundreds of Leaked GitHub App Keys Still Authenticate — www.infosecurity-magazine.com — 23.09.2026 18:00