ADVERTISEMENT

Leaked GitHub key left lead US public health agency’s code exposed to poisoning

Hundreds of breached GitHub app keys still work.

Russian app American
Ann-Marie Corvin
Ann-Marie Corvin Senior Journalist
September 23, 2026 2 min read
Key takeaways:
“The app has write access. It can therefore poison the code stored in them,”
– writes GitGuardian researcher Gaetan Ferry.

Lesser known attack vector

ADVERTISEMENT
NPM worm attack
GitGuardian findings were part of wider investigation against backdrop of supply-chain attacks. Image by Cybernews.

Whose problem?

The app keeps running. The keys keep working. Nobody is watching it,
– warns GitGuardian researcher Gaetan Ferry.
Ann-Marie Corvin
Senior Journalist
ADVERTISEMENT