Broke but Breached: Secret Scanning at Scale on a Student Budget
Ming Chow (Teaching Professor · Tufts University), Raviteja (cloud-native security engineer)
BSides Las Vegas 2025 · Day 1
Overview
This session presents a large-scale secret scanning research effort focused on Visual Studio Code extensions in the public marketplace. The speaker, who introduces herself as Ravita and describes recently completing a master’s in cybersecurity at the University of Maryland College Park, frames the work as a mission to find exposed secrets before attackers do. The talk is explicitly scoped to VS Code extensions because of rapid marketplace growth from roughly 2023 to 2025 and the speaker’s observation that extensions are often bundled with configuration and environmental variables that leak credentials. The narrative connects public-secret leaks to real breaches in principle (the transcript cites SolarWinds in the context of FTP credentials pushed to GitHub as an example of preventable leakage) and argues that pipeline checks could reduce such incidents. The core contribution is operational: how to crawl, download, and scan a very large extension corpus using TruffleHog, Kubernetes, and minimal cloud spend—on the order of under fifteen dollars in the speaker’s account.

Key moments
- 2:00 Speaker introduces the mission: find secrets before attackers, scoped to VS Code extensions and AI-driven marketplace growth.
- 4:00 Architecture pivot: student Azure credits vs DigitalOcean Kubernetes with DaemonSets, Redis queue, Postgres, and Go orchestration.
- 6:00 Tooling stack: TruffleHog, Terraform, Tailscale/K3s history, AWS SQS for VPN queuing, and throughput context.
- 8:00 Collection via sitemap.xml and VSIX URL construction; scanning at ~100 extensions/minute and CPU intensity.
- 10:00 Verified finding categories: GitHub SSH keys, OpenAI, MongoDB, GCP admin escalation claim, Azure SAS, Discord webhooks.
- 12:00 npm token supply-chain angle and four-year-old extension with still-valid token; shift to AI and Hugging Face case study.
- 14:00 Rate limiting: ~116k extensions, IP blacklisting, paid VPN plus AWS FIFO queue with TTL for egress rotation.
- 16:00 Takeaways: sub-$15 cost, logging and alerts, pre-commit secret scanning, and future JetBrains/OpenVSX expansion.
Broke but Breached: Secret Scanning at Scale on a Student Budget
Speakers: Ravita, Cybersecurity (recent graduate, University of Maryland College Park; title/company beyond transcript unknown)
Conference: BSides Las Vegas
YouTube: https://www.youtube.com/watch?v=zKJl2xv-GBw
Overview
This session presents a large-scale secret scanning research effort focused on Visual Studio Code extensions in the public marketplace. The speaker, who introduces herself as Ravita and describes recently completing a master’s in cybersecurity at the University of Maryland College Park, frames the work as a mission to find exposed secrets before attackers do. The talk is explicitly scoped to VS Code extensions because of rapid marketplace growth from roughly 2023 to 2025 and the speaker’s observation that extensions are often bundled with configuration and environmental variables that leak credentials. The narrative connects public-secret leaks to real breaches in principle (the transcript cites SolarWinds in the context of FTP credentials pushed to GitHub as an example of preventable leakage) and argues that pipeline checks could reduce such incidents. The core contribution is operational: how to crawl, download, and scan a very large extension corpus using TruffleHog, Kubernetes, and minimal cloud spend—on the order of under fifteen dollars in the speaker’s account.
Background
▶ Watch: Speaker introduces the mission: find secrets before attackers, scoped to VS C... (2:00)
The speaker positions secrets and breaches as tightly linked: searching for companies breached due to exposed secrets yields many examples, including hard-coded API keys distributed widely. The research motivation is preventive discovery rather than exploitation. VS Code extensions are chosen as a target because marketplace volume is growing, AI-assisted development (“vibe coding” in the transcript) increases the pace of extension publication, and the speaker notes recurring patterns across newly published extensions.
Resource constraints shaped the architecture. As a student, the speaker describes pooling Azure free-credit accounts (approximately one hundred dollars per account, per the talk) from friends to run an initial Kubernetes cluster setup. That first version proved not scalable because secret scanning is CPU-intensive and some virtual machines crashed. The speaker then pivots to Digital Ocean, which offered a two-hundred-dollar student credit line, and describes a revised design using Digital Ocean Kubernetes with DaemonSet pods that pull VS Code Marketplace URLs from a Redis cluster, scan workloads, and write results back, with PostgreSQL as a backup store for larger-scale data. The orchestration stack is implemented in Go for concurrency; Python 3 is mentioned for early proof-of-concept and scraping; Terraform Cloud and Docker appear in the tooling list; Tailscale and K3s are referenced for an earlier multi-account Azure design; AWS SQS is described as supporting a VPN queuing approach at the end of the pipeline to cope with rate limiting and IP blocklisting.
Key Findings
▶ Watch: Tooling stack: TruffleHog, Terraform, Tailscale/K3s history, AWS SQS for VPN ... (6:00)
The scanning pipeline has three conceptual phases: collecting extensions, scanning them, and normalizing findings for presentation. For collection, the speaker rejects naive scraping in favor of using each marketplace site’s sitemap.xml to enumerate extension URLs, then normalizing publisher name, extension name, and latest version via marketplace API calls to build VSIX download URLs. For scanning, TruffleHog is used because it ships with a large built-in ruleset (the speaker states on the order of eight hundred detectors at last check). At the stated scale, the system achieved roughly one hundred extensions per minute, subject to other rate limits.
The speaker distinguishes unverified versus verified findings. Unverified results show many API keys in extensions—ideally zero in a healthy ecosystem. Verified examples discussed in the talk include SSH private keys tied to GitHub (allowing push to repositories in tested cases), OpenAI keys at scale, MongoDB credentials often associated with developers new to extension development, Groq and Anthropic keys aligned with AI-enhanced extensions, GCP project keys (with the speaker stating some findings led to administrator escalation on a small number of accounts), Azure SAS tokens discussed in a supply-chain poisoning framing, Discord webhooks associated with casual “vibe coders,” and GitHub tokens that could be escalated in an OAuth-style chain (details in the talk remain high level).
A concrete npm token case is highlighted: the speaker reports ability to use a leaked token to push JavaScript packages, enabling supply-chain risk, and notes the extension involved had not been updated in approximately four years while the token remained valid—surprising longevity. Supabase tokens are called out as a newer pattern compared with prior scans.
Trend analysis in the talk contrasts eras: around 2022–2023, crypto-era keys such as Infura and blockchain APIs dominated; from 2023–2025, the shift is toward AI-related secrets (OpenAI, Anthropic, Hugging Face). The speaker describes a privacy-preserving case study of a company anonymized as “XYZ”: a Hugging Face token in an extension allegedly allowed downloading unreleased AI models, and a recursive scan of those models reportedly surfaced additional live secrets—presented as one example of chained exposure.
Operational friction included Microsoft download rate limits and IP blacklisting when attempting to fetch on the order of one hundred sixteen thousand extensions. The mitigation described combines a paid VPN service with an AWS FIFO queue of egress IPs, TTL-based backoff, and rotating blocked addresses to the back of the queue until cool-down.
Technical Deep Dive
▶ Watch: Verified finding categories: GitHub SSH keys, OpenAI, MongoDB, GCP admin esca... (10:00)
The session walks through Kubernetes pod layout (shown with a KubeView-style cluster visualization in the talk), DaemonSet distribution across nodes, and the Redis-centered work queue. TruffleHog integration is central; the speaker also mentions calling vendor or platform APIs to resolve ownership metadata for keys such as OpenAI keys (email and related details, per the talk).
The VPN queue mechanism is the most detailed resilience pattern: when scanning saturates Microsoft’s tolerance, IPs land in a FIFO structure with time-to-live so that dequeued addresses are not reused while still hot. This is presented as essential to sustained bulk download plus scan at student-budget scale.
The speaker’s v1 versus v2 evolution illustrates practical constraints of distributed scanning: CPU pressure, cluster sprawl across borrowed Azure accounts, and the need for a single manageable control plane versus horizontally scaled workers.
The talk also briefly extends impact beyond cloud keys: SendGrid-class tokens (as shown in earlier slides in the session, per the speaker’s narration) could enable spam or brand impersonation campaigns at scale. That is not a novel technical claim—email APIs have been abused for years—but it reinforces why “low severity”-looking keys still belong in incident response and communications security programs when validated as live.
Demo / Proof of Concept
▶ Watch: npm token supply-chain angle and four-year-old extension with still-valid tok... (12:00)
The talk does not center on a single live exploit demo in the transcript excerpt. Evidence is presented through aggregate statistics, category breakdowns (OpenAI, MongoDB, GCP, etc.), and narrative verification of selected credentials before the conference. The npm supply-chain escalation and GCP privilege escalation are described as validated by the speaker but without step-by-step reproduction in the recording reviewed here.
Defensive Implications
▶ Watch: Takeaways: sub-$15 cost, logging and alerts, pre-commit secret scanning, and ... (16:00)
The speaker’s defender guidance emphasizes logging and automated alerting when secrets are used from unusual IP locations or in suspicious patterns—visibility as a prerequisite to detection. Maintainer-facing advice includes adopting secret scanning in pre-commit hooks and on GitHub, rotating credentials when found, and avoiding the assumption that force-pushed branches erase history (the transcript references other work on secrets in dangling commits). Organizationally, the talk argues that if a student-scale budget can scan the marketplace, attackers can scale further—treating extension supply chains as part of the attack surface.
For enterprises, the talk is a useful nudge to treat VS Code marketplace installs as unvetted software distribution carrying the same class of leaks as public git history—just packaged for editor convenience. Even if your organization does not author extensions, allowlisting and periodic artifact review can reduce the odds that an employee’s editor introduces a dependency previously scanned and found to embed live cloud credentials.
None of the above replaces issuer-side controls—Microsoft’s marketplace policies, automated scanning, and publisher verification remain the scalable fix—but defenders should assume client-side discovery will continue to outpace centralized review for long-tail extensions.
Key Takeaways
- VS Code marketplace extensions can harbor live API keys, cloud credentials, and private keys; the speaker presents broad unverified counts and multiple verified categories.
- TruffleHog plus a Kubernetes-distributed worker model enabled high-throughput scanning; CPU cost and rate limits are first-class engineering problems.
- Sitemap-driven enumeration plus API-resolved VSIX URLs is the speaker’s preferred collection approach over raw scraping.
- Trends shifted from crypto-era keys to AI-era keys between roughly 2023 and 2025.
- Supply-chain risk appears in the form of long-lived npm tokens and publisher accounts with stale extensions.
- Cost on the order of under fifteen dollars is presented to underline asymmetry: cheap for researchers, cheaper at adversary scale.
- Future work named in the talk includes JetBrains and OpenVSX marketplaces and anonymized metrics to identify developers over-leaking secrets.
About the Speaker(s)
Ravita introduces herself as a recent graduate with a master’s in cybersecurity from the University of Maryland College Park, interested in Go and Kubernetes, a part-time CTF participant, and holding several certifications (listed on slides; not enumerated reliably in the transcript). She states she is seeking employment and thanks NoHack Labs for collaboration on verification, a mentor named Ming for presentation help, the TruffleHog team for open-sourcing the scanner, and Azure and Digital Ocean for student credits. Any employer affiliation at the time of the talk is described as not applicable beyond personal job search context in the session.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Practical, systems-minded secret scanning at real marketplace scale with honest constraints (CPU, rate limits, budget). The TruffleHog-plus-Kubernetes story is reproducible in spirit and the findings—while partly aggregate—include enough verified categories to matter.
Heather Calloway (CISO) — STRONG ACCEPT
This maps cleanly to third-party software supply-chain risk: marketplace-published code with embedded credentials is an procurement and engineering policy problem, not a niche bug-hunting hobby. The speaker’s cost argument is the board-relevant punchline—cheap for a student, cheaper for an adversary.