chiprook
← Security
SecuritySeptember 18, 2026, 12:30

Hardcoded MCP Credentials Found in Public GitHub Files

Hush Security analyzed about 82,000 MCP configuration files on GitHub and found that 12% of credential slots contained keys and tokens in plaintext. 24% of found secrets have broad permissions and do not expire by default, and 243 secrets remained in Git history after removal from the current version.

Hardcoded MCP Credentials Found in Public GitHub Files
#GitHub#MCP
Read next
Security

Kaspersky finds MovieReaper trojan in pirated films, C2 hidden on Solana blockchain

Security

npm Trusted Publishing Abused to Ship GHAPPIER Loader

Security

Orchid Security Delivers AI Readiness Controls With Application-Level Kill Switches

Security

Mandiant: hijacked AI coding session spread Shai-Hulud worm across ~100 repos