Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-21 · updated: 2026-09-21 · tags: [incident] · confidence: high · severity: low · affected_sectors: [global] · au_impact: true

Hush Security analysed around 82,000 publicly accessible Model Context Protocol (MCP) configuration files on GitHub and found 12 per cent of credential slots contained a hardcoded credential literal, potentially exposing credentials for the services those AI coding tools connect to. Of the hardcoded secrets, 55 per cent had no vendor-recognisable token format, including 31 per cent classified as opaque bearer tokens for internal MCP servers; the values were predominantly vendor API keys, bearer tokens and database passwords. The figures are lower-bound estimates, since GitHub code search indexes default branches, excludes forks and caps results per query. Humans are the harder problem: examining the history of 7,681 credential-bearing configurations across up to seven revisions, they found 243 where the secret had been removed from the current file but remained readable in an earlier commit — which means rotation at the provider is the only remediation. Hush's chief executive Micha Rave framed the gap as structural: these files are meant to be committed, the secret never should be, and the highest-risk credentials in them match no known pattern while the identities behind them have no owner and no expiry.

Attribute Detail
Sector AI & Frontier Technology
Date 2026-09-21
Source Help Net Security
Reliability Tier 3