Credential harvesting — the bulk collection of valid credentials — remains one of the most persistent threats to engineering organizations. Unlike phishing, developer machines are especially vulnerable because cloud keys, API tokens, SSH keys, and AI tool caches sit in plaintext on disk, requiring no user deception. Infostealers exploit this by silently reading known credential locations and exfiltrating them. Key statistics: 39% of breaches involve credential abuse across the full attack chain (Verizon 2026 DBIR), 64% of secrets valid in 2022 were still valid in 2026, and 40% of high/critical secrets on developer laptops appear in AI tool directories. Defenses should cover both vectors: phishing-resistant MFA for the social engineering side, and endpoint credential discovery, honeytoken tripwires, short-lived credentials, and fast revocation for the machine-side harvest. GitGuardian's Developer Endpoint Protection product is presented as a solution for the endpoint layer.

15m read timeFrom blog.gitguardian.com
Post cover image
Table of contents
What is credential harvesting?How does credential harvesting work: The two main vectorsWhy developer machines are the richest harvest3 Credential harvesting examplesCredential harvesting malware on the endpointWhat controls miss on the endpoint harvestHow to prevent credential harvestingAuditing the endpoint credential planeThe future of credential harvestingSummary: Harvesting is collection, so reduce what there is to collectFAQs about credential harvesting attacks
76 Impressions