Multi-CloudHow-To & HardeningRetrospectives

How to Detect Leaked Cloud Credentials From Developer Packages

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2025, written in 2026 with the benefit of hindsight.

Supply-chain worms like Shai-Hulud steal cloud credentials from developer machines and CI runners. Here is how to detect leaked credentials and respond quickly.

Step 1: Use provider leak detection

  • GitHub secret scanning (including push protection and partner program alerts) detects secrets in repositories — and, through the partner program, notifies cloud providers like AWS and Microsoft when their credentials appear in public repositories.
  • AWS may notify you and apply the AWSCompromisedKeyQuarantineV2 (or later) managed policy to exposed keys.
  • Microsoft Entra ID Protection includes leaked credentials detection for user passwords (with password hash sync) and can flag leaked service principal credentials.

Make sure those notifications reach a monitored mailbox.

Step 2: Search public repositories for your organization

Monitor GitHub for new public repositories created under employee accounts, especially with suspicious names. Shai-Hulud created repositories to publish stolen secrets.

Step 3: Scan developer environments

Use EDR on developer machines and CI runners. After an ecosystem incident, check for known malicious package versions in lockfiles and caches.

Step 4: Rotate exposed credentials

For any credential possibly exposed:

  1. Rotate or revoke immediately (cloud keys, npm/GitHub tokens, service principal secrets).
  2. Review activity using the credential in CloudTrail, Azure activity logs and Entra sign-in logs.
  3. Remove attacker-created resources.

Step 5: Reduce what's available to steal

  • Developers use IAM Identity Center and Azure CLI with Entra sign-in — short-lived tokens instead of static keys.
  • CI uses OIDC federation.
  • Disable npm install scripts where possible (--ignore-scripts) and use lockfiles.

Verify

Count long-lived cloud credentials on developer machines (target: zero) and confirm leak notifications route to responders.

detect leaked cloud credentialsShai-Hulud npm worm2025

More on this story