# Truffle Security 发现公开 GitHub 仓库中有 543,699 个凭据仍可通过认证

> Truffle Security 测试了 2.24 亿个公开仓库中发现的凭据，报告称 543,699 个仍然有效，暴露时间的中位数为 784 天。这对 Mac 上的开发者意味着什么。

FireAI Security & Research Team (HisnLabs) · Published 2026-10-02
Canonical: https://hisnlabs.com/zh/news/truffle-security-543000-valid-credentials-public-github-repositories

Truffle Security 报告称，它在公开的 GitHub 仓库中发现了 543,699 个独立凭据，在 2026 年 7 月 27 日和 28 日测试时，这些凭据仍可通过认证 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。BleepingComputer 于 2026 年 9 月 30 日报道了这些发现 [[2]](https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/)。所统计的凭据包括云密钥、数据库连接字符串和 AI 服务密钥 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。

## 背景

GitHub 于 2024 年 2 月为所有用户开启了推送保护，这项保护并不涵盖所有凭据格式 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them) [[2]](https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/)。Truffle Security 的分析提出的问题，不同于对新提交的扫描：在一个已有的公开语料库中，哪些凭据仍然有效，以及它们公开了多久 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。

## 发现

语料库来自 The Stack v3 数据集，共有 224,553,295 个仓库和 58,467,468,698 个文件。Truffle Security 针对签发服务测试了每个候选凭据，并按值对凭据去重，因此在 62 个仓库中发现的同一个密钥只计一次 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。抓取只涵盖默认分支，截止于 2025 年 8 月 7 日 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。

公开仓库中有效凭据的年龄中位数为 784 天，第 90 百分位数为 6.3 年；最早的一个提交于 2009 年，至今仍然有效 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。在有效凭据中，Google Cloud 服务账号有 69,041 个，Google API 密钥有 33,343 个，Gemini 密钥有 31,374 个，另有 51,067 个 MongoDB 连接字符串，属于推送保护不拦截的类别 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。

不同服务商的存活情况各不相同。在提交的 101,886 个 npm 令牌中，仍有效的只有 1 个；在提交的 73,048 个 GitHub 令牌中，有 260 个仍有效；而 Postgres 连接字符串，12,985 个中有 11,465 个仍有效，即百分之 88 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。Truffle Security 的结论是，区别在于服务商是否有一条能够接收泄露令牌并使其失效的流程 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。

关于推送保护，报告指出，在其默认开启之后被推送的有效凭据略低于 200,000 个，百分之 51.8 的有效凭据属于它无法识别的类别，受保护的一组下降了百分之 53，而不受保护的一组只下降了百分之 7 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them) [[2]](https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/)。

> FireAI 是 HisnLabs 开发的 macOS 本机防火墙，列出 Mac 上联网的 App 及其访问的目标，并提供按 App 规则加以限制。提供 17 天试用。 [Download FireAI for Mac](https://hisnlabs.com/en/download)

## 对 Mac 用户的影响

这些数据描述的是仓库，而不是电脑，来源也没有说明开发者使用的是哪些操作系统。对 Mac 用户而言，意义在于凭据本身：公开仓库中的密钥可以在任何地方使用，无论创建它的是哪台设备。Gemini 密钥的数量说明，AI 服务密钥与云密钥出现在了同一批数据中 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。

方法本身也限定了这些数字所能说明的范围。凡是被强制推送覆盖、被移到非默认分支，或在 2025 年 8 月之前提交后又回退的内容，这种方法都看不到，因此这个数字是已发现内容的计数，而不是所有暴露内容的计数 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。

## 建议

1. 把已提交的凭据视为一经提交就已失效，无论是否有东西对其作了标记；先轮换，后清理历史，这也是报告的建议 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。
2. 轮换任何曾经提交过的密钥，包括旧分支中的以及后来改为私有的仓库中的，因为有效凭据已公开的时间中位数为 784 天 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。
3. 优先选择会自动过期的凭据；BleepingComputer 的概述把对有效密钥的自动过期列为措施之一 [[2]](https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/)。
4. 把密钥保存在密钥库中，或保存在仓库之外的环境变量中，并在将仓库设为公开之前扫描其历史记录。

## 与 FireAI 的关系

FireAI 是针对一台 Mac 的防火墙。它通过代码签名或路径识别 App，并对该 App 打开的连接应用[按 App 规则](https://hisnlabs.com/zh/docs/per-app-rules)，[活动](https://hisnlabs.com/zh/docs/activity-and-connection-history)页面则列出哪些 App 联网以及去往何处。这有助于用户看到 Mac 上哪些程序会调用云服务或 AI 服务，并编写规则，让只有预期的 App 才能访问。

FireAI 不会扫描仓库或文件中的凭据，看不到加密连接内部的请求内容，也看不到从另一台电脑上使用的密钥。它无法吊销或轮换密钥，也无法移除已经公开发布的凭据。向服务商吊销密钥，才是适用于本报告发现的控制措施。

> 泄露的密钥是在别处使用的，但 Mac 上持有密钥的 App 仍然是从 Mac 联网的。FireAI 保留这些连接的列表，并在出现新连接时先询问。免费试用 17 天。 [Download FireAI for Mac](https://hisnlabs.com/en/download)

## 局限

这些数字来自 Truffle Security 自己的方法和数据集。两份来源对年龄分布的措辞不同：BleepingComputer 表述为大约十分之一的有效凭据已超过 6.3 年，而 Truffle Security 表述为第 90 百分位数为 6.3 年 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them) [[2]](https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/)。文件被提交的日期是语料库提供的唯一的逐文件时钟，因此年龄只是近似值 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。

数据集的抓取截止于 2025 年 8 月，而有效性测试在 2026 年 7 月进行，因此统计中的部分凭据在测试之前已暴露多年，报告无法说明是否有人（如果有的话，是谁）使用过它们 [[1]](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)。

免费试用 [HisnLabs 的 FireAI](https://hisnlabs.com/zh/download) 17 天。

## Sources

- [Truffle Security: 543,699 credentials in public GitHub repos still work, and nobody revoked them](https://trufflesecurity.com/blog/github-repos-exposed-543699-credentials-nobody-revoked-them)
- [BleepingComputer, 30 September 2026: Over 543,000 valid credentials exposed in public GitHub repositories](https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/)
