← Matrix
AML.T0055 realized

Unsecured Credentials

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. bash history), environment variables, operating system, or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. private keys).

> curated attacks (5)

Incident critical 2026-07-16

Malicious Dataset RCE in Hugging Face's Processing Pipeline

A crafted dataset chained two flaws in Hugging Face's dataset-processing pipeline — a remote-code dataset loader and a template-injection bug in dataset config — turning routine ingestion into arbitrary code execution, then credential theft and lateral movement into internal clusters.

Incident high 2026-07-11

GhostCommit: Prompt Injection Hidden in Images Steals Agent Secrets

Attackers concealed instructions inside PNG images that AI coding agents ingest and 'read.' When agents like Cursor and Google Antigravity processed the image, the hidden prompt executed — steering them to collect and exfiltrate developer secrets.

Incident high 2026-06-05

Prompt Injection in Claude Code GitHub Actions Steals CI/CD Secrets

Untrusted text in a GitHub issue or pull request steered a Claude Code GitHub Action into reading process environment variables and CI/CD secrets, then exfiltrating them — turning an automated code agent into a credential-harvesting tool.

Incident critical 2023-09-05

ShadowRay: Exploiting Exposed Ray AI Compute Clusters

Ray's Job API allows remote execution by design and ships without authentication. Thousands of internet-exposed clusters let attackers run code, steal cloud credentials and AI artifacts, and hijack GPUs for cryptomining.

Incident high 2023-01-28

Code Execution & API-Key Theft in MathGPT via Prompt Injection

A public Streamlit app turned GPT-3 output into executed Python. A prompt-injection payload made the model emit code that read the host's environment variables, exfiltrated the app's OpenAI API key, and crashed the service.