Hardcoded MCP Credentials Discovered in Public GitHub Repositories
What Happened — Researchers at Hush Security scanned ~82 000 public GitHub configuration files and found that 12 % contained hard‑coded MCP credentials (API keys, bearer tokens, database passwords). The analysis, based on pattern matching and entropy checks, identified 243 files where secrets had been removed from the latest version but remained in commit history.
Why It Matters for Trust & Control Assurance
- Hard‑coded secrets bypass formal secret‑management controls, creating gaps that continuous control‑assurance programs are built to detect and remediate.
- Persistent secrets in Git history undermine evidence of “least‑privilege” and “secure configuration” controls, making audit trails incomplete.
- Mapping this exposure to a single control objective—Secure Configuration Management—provides assurance evidence that satisfies multiple frameworks (e.g., NIST CSF, ISO 27001).
Who Is Affected
- SaaS and cloud‑native developers
- Organizations that embed MCP (Model‑Coding Platform) services in CI/CD pipelines
- Any enterprise that stores code in public or semi‑public repositories
Recommended Actions
- Deploy automated secret‑scanning tools across all repositories and enforce a “no hard‑coded secret” policy.
- Purge exposed secrets from Git history using tools like BFG Repo‑Cleaner and rotate the compromised credentials immediately.
- Document secret‑management controls in a continuous evidence repository to support audit readiness. Source: https://www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/
Technical Notes
- Exposure vector: public GitHub repositories (misconfiguration / hard‑coded credentials).
- No specific CVE; the risk stems from insecure development practices and lack of secret‑management enforcement.
- Data types exposed include API keys, bearer tokens, and database passwords. Source: https://www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/