🔒Strix Hacking Agent Finds Live GitHub Token in Baseten Repos
A live GitHub token with admin rights was found in Baseten's repos
TL;DR
Strix, an autonomous hacking agent, discovered a live GitHub token with admin rights in Baseten's internal repos. The token, left in a public Docker image, could have been used to tamper with code and supply chain.
Strix, an autonomous hacking agent, found a live GitHub token with admin rights in Baseten's internal repositories. The token, left in a publicly downloadable Docker image, could have been used to tamper with the code other companies rely on to run their models. This incident highlights the importance of securing tokens and monitoring public repositories. The token was created in March 2023 and still worked in July 2026, indicating a significant security lapse. It had admin and push access to Baseten's main product repo, GitOps repo, and Homebrew tap, as well as read/write access to customer-specific private repositories.

Key Points
Strix found a GitHub token with admin and push access to Baseten's main product repo, GitOps repo, and Homebrew tap.
The token had read/write access to customer-specific private repositories, including repos per customers.
The token was left in a publicly downloadable Docker image, allowing unauthorized access to sensitive information.
Strix discovered the token could have been used to tamper with the code other companies rely on to run their models.
The token had admin access to the GitOps repository, which applies the desired state of the clusters to the infrastructure.
Why It Matters
If you're using Baseten's tools or have a GitHub token in a public image, this is a big deal. The token could have been used to tamper with the code other companies rely on to run their models. The incident highlights the importance of securing tokens and monitoring public repositories for sensitive information.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,482 builders reading daily.