Attackers dumped everything they harvested from LiteLLM builds during a 40-minute window in March. Here is what is inside and what it says about where secrets live.
AI agent security is an identity problem, but it often starts as a secrets and credential problem. Do your AI agents operate using static API keys, tokens, and other reusable credentials? They might bypass traditional identity controls, creating a governance blind spot.
A single compromised laptop can mean weeks of manual credential hunting, or hours of clear, prioritized action. See how GitGuardian Developer Endpoint Protection inventories every credential on a developer's machine so your security team can map the blast radius fast. When an attacker compromises a developer laptop, traditional endpoint tools cannot tell you what credentials were exposed.
Every developer laptop is a credential store: secrets hide in.env files, config files, and shell history, and every AI agent on the machine keeps adding more. Most teams already scan repositories and CI pipelines for secrets, but a secret lands on the laptop long before it reaches either one, and that's the place nobody scans. GitGuardian's Developer Endpoint Protection closes that gap.
A new Mini Shai-Hulud wave hit keyv and 800+ npm packages. The malware now scans 469 secret locations, including AI agents, crypto wallets, and CI/CD tools.
A leaked n8n API key is only the start. GitGuardian's research traces the full chain, from exposed tokens and weak keys to CVE-2026-25053 and the N8N_ENCRYPTION_KEY that protects every stored credential, then lays out a hardened configuration to break it.