arXiv · 2609.23042
Secrets That Survive Everything: Runtime Credential Exposure in Production Web Applications
Abstract
Pre-deployment secret scanning operates only on source code, never on what a production application serves. We document two exploitation chains in which Azure AD client credentials and APIM subscription keys from production JavaScript bundles enabled account takeover and mass data exposure. An authorized engagement covered approximately 2,000 enterprise web assets in one organization; 113 (5.65%) served live credentials. To quantify the shift-right gap, we built an independent Ground Truth (GT-194) of 194 secret-grade credentials through Claude Opus 4.7 extraction and manual analyst review, with the 247 LLM-extracted candidates independently validated by GPT-5.5 (Brennan-Prediger kappa = 0.676). The principal finding is structural: 13.9% of GT-194 (27 of 194) is surfaced only by manual analysis and recovered by none of the nine evaluated production scanners, a tool-agnostic blind spot the ground-truth model also misses. CryptoJS encrypted configuration separately defeats every static scanner: the credential exists only after decryption with a co-located key, reached only by runtime-aware detection. Combined coverage plateaus at 86.1%. Among the nine scanners, the best static scanner recovers 36.6% and the best runtime-aware scanner 77.8% (F1 = 0.818, McNemar p < 0.001); the ground-truth model is reported separately as a reference comparator, not an evaluated detector. On 63 of 86 secret-exposed applications (73.3%), the full Azure AD token-mint chain is co-located in one bundle, reachable from browser code. We characterize five paths by which credentials reach production undetected and present a layered runtime detection methodology and remediation framework. Recall is scoped to a single-organization Azure-heavy corpus.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Hemanth Gorijala. 2026-09-19. Secrets That Survive Everything: Runtime Credential Exposure in Production Web Applications. https://doi.org/10.1109/access.2026.3734984
Cite the original work for its findings. Save a collection to share your selection of sources.