Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 3IT NewsSecurity

Hardcoded MCP Credentials Found in Public GitHub Files

Help Net Security, Friday, September 18th, 2026

Twelve percent of credential slots in 82,000 public MCP config files contained a hardcoded secret.

Hush Security analyzed roughly 82,000 MCP configuration files in public GitHub repositories and found that 12% of credential slots held a hardcoded credential literal, exposing connected services and systems.

Researchers classified each slot as a hardcoded value, environment-variable reference, client-managed prompt, secret-manager reference, placeholder or empty field, then identified likely secrets using provider-specific patterns and Shannon entropy.

Of the hardcoded secrets, 55% had no vendor-recognizable token format, including 31% classified as opaque bearer tokens for internal MCP servers, and the values were predominantly vendor API keys, bearer tokens and database passwords.

more →  ·  More from Security →