Monthly credential-leak report

The live secrets accidentally shipped

Every month we scan newly published open-source packages for real, still-working credentials — then quietly notify the owner before anyone else knows. Sliced by when each npm package was actually published, the leak rate holds a steady baseline: 1,600 npm packages in the first eight months of 2026 shipped a working, high-impact key.

npm · live keys by publish month

npm only — the one ecosystem with a reliable publish date. Latest-version release date; complete months of 2026.

Reviewed each month

What we checked, month by month

These counts follow our review cadence across all ecosystems — not the ecosystem's leak rate. The mid-2026 peak is a one-time backfill: we re-validated years of already-published packages within a few months. As that backlog clears, the monthly figure settles toward the live rate — so read it as throughput, not as a rise or fall in leaks. For the true rate of new leaks, see the publish-month baseline above.

packages flagged in this month's review as carrying a live, high-impact secret — each one a working key to someone's data, code, infrastructure or budget.

Top 10 · live high-impact keys

packages affected