Business
Individual
Partners
Intelligence
How we work
Sign in Check my firm
Glossary › Patterns › Code / repository leak
Reference · Pattern

API keys committed to public GitHub repositories

Severity CriticalKind Code / repository leakEffort to fix ModerateUpdated 29 Sep 2026By LeakTrace
Definition

Employee or contractor GitHub accounts host public repositories containing plaintext API keys, cloud credentials, or database connection strings for the corporate tenant.

What it is

GitHub secret-scanning catches the largest providers (AWS, Stripe, Google Cloud, GitHub itself) and revokes on push. That leaves a long tail of less-scanned credentials, CRM tokens, marketing platform keys, e-sign vendor keys, custom-built internal API keys, that stay live in public repositories for months. Bots harvest new public commits within minutes; live credentials get weaponized within hours.

Why it matters

Even non-cloud API keys map to lateral-movement paths. A CRM key exposes the customer list. A marketing platform key exposes engagement analytics and can be abused to send authentic-looking phishing from a trusted sender. A helpdesk key opens ticket history that names internal systems and privileged users.

How anyone can check it

Search public code for your domain name and for words like “password” or “key” next to it.

Remediation direction

Daily scanning of public GitHub for corporate domain mentions, employee handles, and known internal project names, combined with a fast-path secret rotation runbook (identify credential owner, rotate, review access logs for the exposure window). Longer term: mandatory pre-commit secret scanning on every corporate laptop and contractor workstation.

LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.

See what is open from outside before anyone else does. Check my firm →