GitGuardian found 474 publicly exposed GitHub App RSA private keys that still authenticated as 440 distinct apps out of 4,802 GitHub-context keys examined. Because GitHub App private keys can remain valid indefinitely, an attacker with a leaked key can mint API tokens indistinguishable from those issued by the legitimate app and impersonate it.
The valid credentials included keys linked to a shared GitHub Actions token app, CDC-related infrastructure, BuildBuddy, and the unmaintained Crusher.dev framework. Affected apps could retain access to private repositories and permissions to modify code, administer organizations, manage self-hosted runners, or control workflows; organizations should rotate exposed App keys immediately and continuously monitor public sources for credential leaks.

See attribution, scope, and your downstream exposure.
9 events from the most recent confirmed update back to the earliest known activity.
A private key for BuildBuddy's internal development GitHub App leaked. The App had write and administration rights to BuildBuddy's main repository, potentially affecting its CLI users, self-hosted servers, and SaaS platform.
A private key for a private GitHub App owned by cdcent leaked in a CDCGov repository. The App could write to two private CDC repositories, including one apparently mediating between CDC repositories and Azure infrastructure.
A private key for the Access Tokens for GitHub Actions App leaked. The App was installed in roughly 300 organizations, including Civica and Sierra Nevada Corp., and had repository-modification and organization-administration permissions.
A private key for the Crusher.dev test-framework GitHub App leaked. The framework was later reported as unmaintained, leaving organizations that retained its installation exposed to private-code theft.
GitGuardian reported that affected Apps included permissions to read private repositories, write private repository content, administer organizations, manage self-hosted runners, and control workflows. It warned that these permission combinations could enable organization takeover or code execution on internal infrastructure.
GitGuardian analyzed more than 500,000 publicly exposed RSA private keys and identified 4,802 GitHub-context keys associated with App IDs. Of those, 474 still authenticated to GitHub and corresponded to 440 distinct GitHub Apps, allowing impersonation and token minting as the legitimate Apps.
The maintainer of Access Tokens for GitHub Actions rotated its exposed key after GitGuardian's disclosure, and BuildBuddy took down its exposed App and said it found no evidence of malicious use.
The credentials associated with the exposed CDC-related GitHub App key were revoked following GitGuardian's disclosure.
GitGuardian reported the CDC-related exposed credential through the HHS disclosure portal. GitGuardian assessed that the key could potentially enable arbitrary code execution in the CDC Azure tenant, but stated it did not interact with the repository.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcereddit.com
Open sourceblog.gitguardian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.