Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

Secrets That Survive Everything: Runtime Credential Exposure in Production Web Applications

A ground-truth study of 194 live credentials across ~2,000 enterprise web assets reveals a structural blind spot in pre-deployment secret scanning
Hemanth Gorijalaยท 2026ยท DOI 10.48550/arXiv.2609.23042

The core problem

Secret scanning has matured into a standard pre-deployment control: pipelines inspect repositories, commits, and build artifacts for high-entropy strings and known credential patterns. The implicit assumption is that if the source is clean, the deployed application is clean. This paper challenges that assumption directly. Pre-deployment scanning operates only on source code, never on what a production application actually serves to a browser.

The authors document two exploitation chains in which Azure AD client credentials and APIM subscription keys, embedded in production JavaScript bundles, enabled account takeover and mass data exposure. The study is framed around a "shift-right gap": the distance between what static, pre-deployment tooling can see and what a runtime-aware observer can recover from live production traffic and bundles.

The central research question is structural rather than tool-specific: is there a class of production credential exposure that no combination of current scanners can detect, and if so, how large is it? The answer, developed through an independent ground truth and a nine-scanner evaluation, is yes โ€” and it is not marginal.

Innovation

Of the approximately 2,000 enterprise web assets examined, 113 (5.65%) served live credentials. This is the headline prevalence figure: roughly one in eighteen production assets exposed usable secrets at runtime.

The principal finding is structural. Of GT-194, 13.9% (27 of 194) was surfaced only by manual analysis and recovered by none of the nine evaluated production scanners. This is a tool-agnostic blind spot: the ground-truth model also misses it, meaning the gap is not an artifact of any single detector's design.

CryptoJS-encrypted configuration separately defeats every static scanner. In these cases the credential does not exist as a recognizable string until decryption with a co-located key, and is therefore reachable only by runtime-aware detection. Combined coverage across all scanners plateaus at 86.1%.

Among the nine scanners, the best static scanner recovers 36.6% of GT-194, while the best runtime-aware scanner recovers 77.8% ( = 0.818, McNemar p < 0.001). The gap between 36.6% and 77.8% is the empirical core of the shift-right argument.

Exposure is not merely credential leakage; it is frequently a complete compromise path. On 63 of 86 secret-exposed applications

Secret scanning has matured into a standard pre-deployment control: pipelines inspect repositories, commits, and build artifacts for high-entropy strings and known credential patterns. The implicit assumption is that if the source is clean, the deployed application is clean. This paper challenges that assumption directly. Pre-deployment scanning operates only on source code, never on what a production application actually serves to a browser.
The authors document two exploitation chains in which Azure AD client credentials and APIM subscription keys, embedded in production JavaScript bundles, enabled account takeover and mass data exposure. The study is framed around a "shift-right gap": the distance between what static, pre-deployment tooling can see and what a runtime-aware observer can recover from live production traffic and bundles.

Why it matters

The authors characterize five paths by which credentials reach production undetected. These paths explain why static scanning, however well tuned, cannot close the gap: the secret may be absent from source, transformed at build time, encrypted with a co-located key, injected at runtime, or assembled only in the browser's execution context.

The 13.9% manual-only stratum is the most consequential result. It implies that even a perfect ensemble of the nine evaluated scanners would miss roughly one in seven secret-grade credentials, and that human analyst review remains a necessary โ€” not merely supplementary โ€” control. The CryptoJS case is a sharper version of the same point: encryption with a co-located key is not a security control against a runtime observer, because the key travels with the ciphertext.

The 73.3% co-location figure reframes severity. When the full Azure AD token-mint chain sits in one bundle, the marginal effort for account takeover approaches zero. This is consistent with the two documented exploitation chains and suggests that credential exposure should be triaged by reachable compromise path, not by credential count alone.

In response, the paper presents a layered runtime detection methodology and a remediation framework. The layered approach combines runtime-aware scanning with manual review and treats encrypted configuration as a first-class detection target rather than a static-scanning edge case. The authors are explicit about scope: recall is measured on a single-organization, Azure-heavy corpus, so the absolute percentages should be read as a lower bound on the structural gap rather than a universal prevalence estimate.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ