Back to news

AI Coding Tools and Leaked Credentials Expose New Git Security Risks

Two separate incidents reveal how developer workflows — from AI coding assistants to contractor practices — are quietly leaking sensitive repository data.

AI Coding Tools and Leaked Credentials Expose New Git Security Risks

What happened

Security researcher cereblab discovered that xAI's Grok Build coding CLI, tested at version 0.2.93, was transmitting entire Git repositories — including full commit histories — to an xAI-operated Google Cloud Storage bucket, well beyond the scope of files relevant to any given coding task. By intercepting one such upload and extracting the bundled repository, the researcher was able to recover a file the agent had been explicitly instructed to leave untouched. Separately, CISA published a postmortem on a months-long data exposure in which a contractor inadvertently committed dozens of internal credentials — including AWS GovCloud access keys — to a public GitHub repository, where they sat undetected for nearly six months until KrebsOnSecurity flagged the issue to the agency.

Why it matters for your business

Both incidents share a common thread: organizations are losing visibility into where their source code and credentials actually travel. AI-powered developer tools introduce a new attack surface that many security teams have not yet mapped — any tool with filesystem or shell access could be silently exfiltrating intellectual property or secrets embedded in commit histories. The CISA case underscores that even well-resourced government agencies can fail to detect exposed credentials for extended periods, meaning most private-sector teams face at least equal risk. Practical steps include auditing the network behavior of every AI coding assistant before deployment, enforcing pre-commit hooks that scan for secrets, and establishing automated monitoring for credentials appearing in public code repositories.

What to watch next

xAI has not yet issued a public statement clarifying whether the repository uploads are intentional product behavior or an unintended data handling flaw, and it remains unclear whether any third parties accessed data stored in the GCS bucket. On the policy side, CISA's postmortem is expected to inform updated contractor security requirements, which could eventually set a new baseline for how federal vendors manage code repositories and credential hygiene — a standard that often migrates into enterprise procurement expectations over time.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp