appsec.fyi

Secrets — A Practical Guide

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

Secrets: A Practical Guide

Curated and synthesized by . Last updated 2026-10-01. Synthesized from 253 of 253 curated resources. Browse all 253 Secrets resources →

Problem Framing

The proliferation of secrets—API keys, credentials, certificates, and tokens—across the software development lifecycle presents a persistent and evolving threat landscape. Historically, secrets were primarily found embedded in source code repositories. However, the modern attack surface for secrets has dramatically expanded. This includes CI/CD pipelines, cloud infrastructure, developer endpoints, collaboration tools, and, critically, the integration of AI-powered development tools.

The consequences of secret exposure are severe, ranging from unauthorized access to sensitive data and systems, financial loss through resource abuse, to full-scale account takeover and the compromise of entire organizational infrastructures. The increasing sophistication of attackers, coupled with the speed at which AI can discover and exploit vulnerabilities, necessitates a proactive and multi-layered approach to secrets management and security.

Recent trends indicate a significant rise in secrets leakage, particularly linked to AI. AI coding agents, while boosting developer productivity, are creating new vectors for secrets exposure by storing or processing sensitive information in ways that traditional security scanners cannot detect [1][2]. The sheer volume of code generated and the complexity of AI workflows amplify the potential for secrets sprawl [3]. Furthermore, the automation inherent in AI and CI/CD processes allows for machine-speed attacks where discovered secrets can be exploited rapidly, collapsing the time between compromise and impact [4][5].

Core Mechanics

Secrets are exposed through a variety of mechanisms, often falling into categories of accidental leakage, misconfiguration, or intentional malicious actions. Understanding these core mechanics is crucial for effective defense.

Accidental Leakage and Developer Workflow Vulnerabilities

Developers inadvertently expose secrets through several common practices:

CI/CD Pipeline Vulnerabilities

The automation and privileged access within CI/CD pipelines make them prime targets:

Cloud Infrastructure and Service Misconfigurations

The complexity of cloud environments introduces numerous opportunities for secrets exposure:

AI-Specific Attack Vectors

AI introduces novel attack vectors and amplifies existing ones:

Notable Techniques

Several advanced and emergent techniques are employed by attackers and defenders alike.

Credential Harvesting and Exfiltration

Exploiting AI Agent Vulnerabilities

Leveraging Git History and Repository Access

Supply Chain Worms and Package Poisoning

Detection & Prevention

A robust defense strategy for secrets involves a layered approach, integrating detection at multiple points in the development lifecycle and implementing strict preventative controls.

Shift-Left Detection and Prevention

Secrets Management and Rotation

Code and Configuration Hardening

Non-Human Identity (NHI) Governance

With the rise of AI agents and automated systems, managing non-human identities and their associated secrets is paramount. This includes:

Response and Remediation

Tooling

A robust secrets security program relies on a diverse set of tools, spanning detection, prevention, management, and remediation.

Detection and Scanning

Secrets Management

Remediation

Specialized Tools

Recent Developments

The landscape of secrets security is rapidly evolving, driven by advancements in AI, cloud-native architectures, and increasingly sophisticated supply chain attacks.

AI's Escalating Impact

AI is a double-edged sword in secrets security. On one hand, AI-powered tools are detecting secrets at an unprecedented scale and speed. GitGuardian, for instance, detected 28.6 million new hardcoded secrets on public GitHub in 2025, a 34% increase year-over-year, with AI-assisted commits contributing to this surge [47][4][5]. AI-service leaks have surged 81% year-over-year [29][12].

On the other hand, AI coding agents are becoming significant vectors for secrets leakage. They store credentials in locations often missed by traditional scanners, such as config files, environment variables, logs, and cache directories [1][2]. The integration of AI agents with various services and their ability to execute commands with broad privileges amplify the risk of prompt injection attacks leading to credential exfiltration [25]. Concerns are also rising about AI models trained on public datasets inadvertently leaking secrets present in that data [3].

Supply Chain Sophistication

Supply chain attacks continue to evolve, with increasingly stealthy and pervasive malware. Worms like Shai-Hulud and its variants (ChainDrop, Mini Shai-Hulud) are notable for their ability to self-propagate through package managers (npm, PyPI, SAP npm packages) and infect developer machines and CI/CD runners. These worms can harvest a wide range of credentials, including cloud keys, tokens, and AI tool configurations, exfiltrating them to attacker-controlled infrastructure [27][28][15]. The use of Bun JavaScript runtime in these stealers provides a portable execution vehicle [14][15].

Compromises of CI/CD actions, such as tj-actions/changed-files and @redhat-cloud-services npm packages, allow attackers to steal secrets directly from build logs or execute malicious code during the build process [13][48]. The attack on the elementary-data PyPI package demonstrated how a compromised GitHub Actions pipeline could publish a credential-stealing package [16].

Cloud Native and Container Security Challenges

The adoption of cloud-native architectures, including Kubernetes and containerization, introduces new complexities for secrets management. Hardcoded secrets in Docker images or insecure configurations of services like Spring Boot Actuator can lead to significant exposure [49][50][17]. Discovering thousands of Docker Hub images exposing live cloud credentials, including AI LLM model keys, highlights this persistent problem [17]. Attackers are also targeting cloud metadata services for credentials via techniques like HTTP 303 SSRF [18][19].

Non-Human Identity (NHI) and Automation

As more automation and AI agents are deployed, managing Non-Human Identities (NHIs) becomes critical. These identities often have privileged access and can be overlooked by traditional human-centric security controls. Leaked API tokens for automation platforms like n8n have been found to grant unauthorized access to connected services, sometimes without expiration dates [22][23]. The broad permissions often granted to CI/CD service accounts and AI agents create significant risks if these identities are compromised [8][1].

Historical Persistence and Detection Gaps

Secrets embedded in Git history remain a persistent problem. Even if removed from the current codebase, they can often be recovered from past commits, and many remain valid for years [10][35]. Traditional SAST and DAST tools struggle to comprehensively address secrets security because they often focus on vulnerabilities rather than active access or the sheer sprawl of secrets beyond code repositories [47]. The trend of secrets appearing in collaboration and productivity tools outside of code repositories further exacerbates this detection gap [47].

Where to Go Deeper

To further your understanding and implementation of robust secrets security practices, consider exploring the following resources and topics:

Comprehensive Guides and Reports

Technical Deep Dives and Tooling

Best Practices and Frameworks

Sources cited in this guide

  1. AI Coding Agents Are Leaking Credentials: Cursor, Claude Code, Copilot, and MCP — blog.gitguardian.com
  2. Every Laptop Is a Credential Store: Where Secrets Hide — blog.gitguardian.com
  3. Leaking Secrets in the Age of AI — wiz.io
  4. 29 Million Leaked Secrets: How AI Coding Tools Are Making It Worse — helpnetsecurity.com
  5. 29 Million Secrets Leaked: AI Coding Tools Making It Worse — turbogeek.co.uk
  6. Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack — ethiack.com
  7. 8 Best Secret Scanning Tools (2026) — appsecsanta.com
  8. The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub — wiz.io
  9. The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments — wiz.io
  10. Credential Harvesting Explained: How Attackers Collect Secrets From Developer Machines — blog.gitguardian.com
  11. Browser Stored Credentials — ipurple.team
  12. The State of Secrets Sprawl 2026: AI-Service Leaks Surge 81% — blog.gitguardian.com
  13. GitHub Action tj-actions/changed-files supply chain attack: everything you need to know — wiz.io
  14. lightning PyPI Compromise: A Bun-Based Credential Stealer in Python — snyk.io
  15. Supply Chain Campaign Targets SAP npm Packages with Credential-Stealing Malware — wiz.io
  16. Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers — snyk.io
  17. 10K Docker Images Spray Live Cloud Creds — theregister.com
  18. The HTTP 303 SSRF Hack : From Python HTTP Client Defaults to AWS Credential Exfiltration. — infosecwriteups.com
  19. The many ways to obtain credentials in AWS — wiz.io
  20. From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies — unit42.paloaltonetworks.com
  21. What happened after we pushed our .env to a public repo — tachyon.so
  22. No Hack Required: How Thousands of Leaked API Tokens Left Automation Servers Wide Open — ibtimes.sg
  23. Mini Shai-Hulud's Latest Wave: 280 New Places It Hunts for Your Secrets — blog.gitguardian.com
  24. Microsoft Copilot Cowork Exfiltrates Files — promptarmor.com
  25. A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity — unit42.paloaltonetworks.com
  26. Generative AI Security: Are Your Developers Pasting Secrets Into LLMs? — blog.gitguardian.com
  27. What Was on This Machine? Answering the Blast Radius Question After a Laptop Compromise — blog.gitguardian.com
  28. TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack — snyk.io
  29. AI Is Fueling Secrets Sprawl: GitGuardian Reports 81% Surge of AI-Service Leaks — blog.gitguardian.com
  30. An AI Agent Breached Hugging Face. The Attack Playbook Was Older Than the Attacker — blog.gitguardian.com
  31. Code to Cloud Attacks: From Github PAT to Cloud Control Plane — wiz.io
  32. Gitleaks vs TruffleHog 2026 Benchmarks (AppSec Santa) — appsecsanta.com
  33. Top 16 Secrets Management Tools and Platforms for 2026 (Compared) — blog.gitguardian.com
  34. SEC02-BP03 Store and use secrets securely (AWS Well-Architected) — docs.aws.amazon.com
  35. 23.8 Million Secrets Leaked on GitHub: The Case for Expiring Credentials — zerohost.net
  36. AWS Secrets Manager: Secure Credential Storage & Best Practices — sedai.io
  37. Integrating HashiCorp Vault with Kubernetes for Secrets Mgmt — dev.to
  38. HashiCorp Vault Kubernetes: The Definitive Guide (Plural) — plural.sh
  39. Do Not Use Secrets in Environment Variables — nodejs-security.com
  40. Under the Radar: Exploring Spring Boot Actuator Misconfigurations — wiz.io
  41. Top 8 Git Secrets Scanners in 2026 — jit.io
  42. Lessons Learned from CISAs Recent GitHub Leak — krebsonsecurity.com
  43. Thousands of Corporate Secrets Were Left Exposed. This Guy Found Them All — wired.com
  44. Secret Scanning Encoded and Archived Data — trufflesecurity.com
  45. How TruffleHog Verifies Secrets — trufflesecurity.com
  46. maxgoedjen/secretive — github.com
  47. Why SAST and DAST Aren't Enough for Secrets Security — blog.gitguardian.com
  48. Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm — aikido.dev
  49. Leaked Env Variables Allow Large-Scale Cloud Extortion — unit42.paloaltonetworks.com
  50. CVE-2025-68429: Storybook .env Secrets Exposure — miggo.io
  51. OWASP/wrongsecrets — github.com
📚 This guide is synthesized from the full text of resources curated in the Secrets library, and refreshed as new material is added.