Skip to content
Intruder Reveals 42,000 Exposed Tokens in Web Applications

Intruder Reveals 42,000 Exposed Tokens in Web Applications

First seen 10 Jan 2026, 11:51 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Cybersecurity company Intruder has detected over 42,000 leaked tokens in JavaScript bundles of single-page applications. The London-based firm scanned 5 million applications using a new spidering-based method, uncovering sensitive development and collaboration credentials. This discovery highlights a significant issue with exposed secrets in web apps.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Intruder in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed