TruffleHog: The Secret Scanner Attackers Use Too

By Andrew Owens |

If you've done any security work in the last few years, you've probably heard of TruffleHog. It's an open source tool from Truffle Security that finds secrets (API keys, passwords, tokens) in places they shouldn't be: code, git history, logs, Slack, wikis, and a lot more.

It's a good tool. I'd recommend it to anyone. The problem is that attackers agree.

What it does

Lots of tools can search for strings that look like an AWS key. TruffleHog goes a step further and checks whether the key actually works. When it finds an AWS key, for example, it makes a harmless API call to see if the key is live. According to Truffle Security, it can do that for more than 800 kinds of secrets.

So instead of a list of maybe-secrets, you get a list of confirmed, working credentials. For a defender that's great, because you know exactly what to rotate first. For an attacker it's even better, because they know exactly which keys to use.

How attackers use it

A few real examples:

The Shai-Hulud npm worm. In September 2025, a self-replicating worm spread through the npm package registry. When a developer or a CI server installed an infected package, it ran TruffleHog on the machine, collected every working secret it found, and published them to public GitHub repositories. Then it used any npm tokens it found to infect more packages. It hit hundreds of packages.

TruffleNet. Security researchers described a campaign built around TruffleHog that took stolen AWS keys, used TruffleHog to check which ones worked, and then used the working ones to send email through Amazon's email service. Stolen cloud keys turned into a phishing operation running on someone else's bill.

Just scanning public stuff. The simplest use is pointing it at public GitHub repos, public Docker images, and websites, and waiting. Leaked keys are found fast. Truffle Security even wrote a post about what it means when you see TruffleHog's user agent in your own logs. Sometimes it's your security team. Sometimes it's someone testing whether your leaked key still works.

Where your secrets actually leak

Most leaked secrets end up in one of a few places:

  • Git history. Someone committed a .env file, then deleted it in the next commit. It's still in the history.
  • Frontend code. A key that was supposed to stay on the server ended up in the JavaScript bundle every visitor downloads. AI coding tools do this a lot.
  • Files left on the web server. An exposed .env or .git folder, a backup file, a config file in the wrong directory.
  • Error pages and debug output. A stack trace that dumps environment variables.
  • CI logs and Docker images. A build step that printed a secret, or an image with credentials baked in.

Where a pen test helps

A pen test looks at your live app from the outside, which is exactly where an attacker starts. Part of that is looking for secrets exposed on your public surface: API keys in responses and JavaScript, reachable .env and .git files, config files and backups sitting on the server, debug pages that say too much.

Those are the leaks that don't need an infected package or an insider to find. Anyone can pull them from your website. A pen test finds them before someone running TruffleHog against your domain does.

Where it doesn't

A pen test from the outside won't see your private repos, your developers' laptops, your Slack, or your CI logs. For those, you need secret scanning on your own systems. So:

  1. Run TruffleHog yourself. On your repos, including full history. On your CI logs. It's free.
  2. Add it to CI and pre-commit so new secrets get caught before they're pushed.
  3. Use a unique user agent suffix when you scan (TruffleHog has a flag for it), so your own scans are easy to tell apart from someone else's in the logs.
  4. Rotate, don't just delete. If a secret was exposed, deleting the file or the commit isn't enough. Assume it was copied. Revoke it and issue a new one.

The short version

Attackers have automated finding your leaked keys. The only answer is finding them first. Scan your own repos and pipelines with TruffleHog, and get your public app tested from the outside.

The free scan takes ten seconds. The $495 pen test goes looking for exposed secrets on your live site, along with everything else.

Ready to fortify your defenses against cyber threats?

Start Your Penetration Test Now