GitGuardian counted 28,649,024 new hardcoded secrets in public GitHub commits in 2025. That is a 34 percent rise from 2024, the largest jump in their series. Teams still treat a global filename:.env password search as recon. It is a firehose.
The index still holds the secrets. The query has to name an org, a user, or a domain. Unscoped dorks produce a feed. Scoped dorks produce a target.
Two search languages, one trap
GitHub now ships two code-search dialects. The website uses the 2023 code search syntax. Qualifiers are path:, org:, repo:, language:, and NOT is:fork. filename: is not in that table.
The REST endpoint GET /search/code still speaks the legacy search API. There filename:.env and user:acme still work. A token is required. Rate limits are 10 requests per minute on the core search route.
Paste a 2018 cheat sheet into github.com/search and the hits look empty. The operator did not die. The qualifier did. path:/(^|\/)\.env$/ is the current way to pin a basename. path:*.pem is the glob form.
mago.team github_dorks talks to the REST search API. It scopes user:{target} for a handle, or "domain.tld" as a quoted term for a company site. The spell needs a free GH_TOKEN. Without it the job is skipped, not faked.
Queries that still hit in 2026
Keep the org in every query. Drop the rest of GitHub.
org:TARGET path:/(^|\/)\.env$/ AWS_SECRET
org:TARGET path:*.pem "BEGIN PRIVATE KEY" NOT is:fork
org:TARGET "AKIA" NOT is:fork NOT path:test
org:TARGET path:*.npmrc _authToken
org:TARGET "xoxb-" OR "xoxp-" NOT is:fork
REST equivalents for a script:
filename:.env AWS_SECRET user:TARGET
filename:.pem "BEGIN PRIVATE KEY" user:TARGET
AWS_SECRET "TARGET.com"
GitGuardian's 2026 report put AI-assisted commits at roughly twice the leak rate of the GitHub-wide baseline. Generic secrets remain the majority class. Partner push protection still misses DATABASE_URL, home-grown bearer tokens, and .npmrc _authToken lines.
A 2025 InfoQ write-up of the prior report put generic credentials at 58 percent of detected leaks. A regex that only fires on Stripe and AWS misses most of the volume. Scoped .env search still pays.
What a hit is not
A code-search hit is a public string in a default-branch blob under 384 KB. It is not proof the secret is live. It is not proof the repo is still the company's. Forks copy history. Vendored trees copy other people's keys.
GitHub documents is:fork, is:archived, is:vendored, and is:generated. Exclude them on the first pass.
org:TARGET path:/(^|\/)\.env$/ NOT is:fork NOT is:archived
Do not open the credential. Rotate if it is yours. File a disclosure if it is not. Pasting a live key into a chat is a second leak.
Run it as a pipeline
A useful pass is three buckets, not 200 dorks.
- Env and config:
.env,.npmrc,credentials,docker-compose*.yml. - Key material: PEM,
AKIA, Slackxoxb-, Stripesk_live_. - Company string: the apex domain next to
passwordorapi_key.
Record the query, the total_count, and three sample paths. That is enough to decide the next hop: rotate, disclose, or ignore.
mago.team runs that pass as github_dorks on a handle or org. Hits land in the same report as DNS, WHOIS, and JS. The hunt is one selector. The dorks are one spell, not a weekend of curl.
Why the 2018 lists still circulate
Cheat sheets keep listing filename:.env password with no org. That query searches the planet. GitHub code search ranks recent public blobs. The first page is random startups, course repos, and copied Docker samples.
GitGuardian's 2026 public-relations note added two numbers that matter for hunters. Secret leak rates in AI-assisted commits ran about double the GitHub-wide baseline across 2025. MCP config files in the study exposed 24,008 unique secrets. Copilot-enabled public repos in the 2025 report leaked at 6.4 percent, against 4.6 percent overall.
Those are volume stats. They do not tell you which org is yours. An unscoped dork of AKIA will show AWS keys that are not in your incident. An org:TARGET AKIA query either hits or it does not. That is the difference between a feed and a case.
The 2025 report also said 70 percent of secrets leaked in 2022 were still valid years later. Rotation is the control. Search is how you find the copy that nobody rotated. Scope the search or you will rotate the wrong tenant.
REST search indexes default branches and files under 384 KB. History-only leaks need git log -p on a clone, or a tool that walks commits. Code search will not see a key that lived in one commit and was rewritten out of HEAD. Say that in the report. Do not claim "GitHub is clean" because total_count was zero.
Global cheat sheets will keep circulating. They search the planet. The incident is in one org.
Top comments (0)