logo

Hackers ramp up scans for leaked Git tokens and secrets

ID: 7ffab828-75d3-5d57-b88b-eaf93f0c0d77

STIX ID: report--7ffab828-75d3-5d57-b88b-eaf93f0c0d77

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-04-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GreyNoise observed a major spike in internet-wide scanning for exposed Git configuration files on April 20–21, 2025 — nearly 4,800 unique IPs daily — with activity concentrated in Singapore, the U.S., Spain, Germany, the UK, and India. Such scans hunt for .git/config files that can contain credentials and tokens; past operations (e.g., EmeraldWhale) used the same technique to steal thousands of cloud credentials and enabled breaches like the Internet Archive compromise, so organizations should block access to .git directories, monitor logs for suspicious access, and rotate any exposed credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.