Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 3 › IT News › Security

Hardcoded MCP Credentials Found in Public GitHub Files

Help Net Security, Friday, September 18th, 2026

Twelve percent of credential slots in 82,000 public MCP config files contained a hardcoded secret.

Hush Security analyzed roughly 82,000 MCP configuration files in public GitHub repositories and found that 12% of credential slots held a hardcoded credential literal, exposing connected services and systems.

Researchers classified each slot as a hardcoded value, environment-variable reference, client-managed prompt, secret-manager reference, placeholder or empty field, then identified likely secrets using provider-specific patterns and Shannon entropy.

Of the hardcoded secrets, 55% had no vendor-recognizable token format, including 31% classified as opaque bearer tokens for internal MCP servers, and the values were predominantly vendor API keys, bearer tokens and database passwords.

more →  ·  More from Security →