MOXFIVE Threat Actor Alert - Git Credential Exposure

Every month, we take a look at a current threat actor. If you would like to receive this via email each month, click below to subscribe to the MOXFIVE mailing list.

Additional Threat Actor Spotlights are available on our
Resources page >>

Subscribe
April 10, 2026

Social Engineering and Git Credential Exposure

Threat actors are increasingly combining social engineering with Git credential harvesting, platforms such as GitHub, GitLab, and Bitbucket; using compromised developers as the entry point into production infrastructure and software supply chains. A compromised developer credential can provide access to production systems, customer data, cloud environments, and every downstream consumer of that code.

Recent Activity Overview

Recommendations

How MOXFIVE Can Help

The MOXFIVE Digital Forensics and Incident Response (DFIR) team provides deep technical and investigative experience combined with our agentic forensics platform to quickly deliver reliable and actionable findings for our clients.

The MOXFIVE Business Resilience team provides proactive security services and strategic advisory support backed by MOXGUARD. If you need ongoing advisory guidance or to strengthen your developer security posture prior to an incident, reach out to our team at proactive@moxfive.com.

If you have questions or are experiencing an incident, contact us at 833-568-6695 or email our team at incident@moxfive.com.