- Sources: researcher writeup, HN 49034292
- Summary: A researcher decrypted the firmware of Hanwha Vision security cameras, ran a secret scanner over the root filesystem, and found a GitHub token embedded in roughly 30 files, including the camera login UI. The token held admin access to hundreds of repositories in Hanwha's GitHub organization. The root cause was a Vite build step that exported the entire CI environment (
process.env), including a GITHUB_NPM_TOKEN, into the shipped frontend bundle. Hanwha responded within 12 hours of disclosure and confirmed the token was revoked. The writeup also reports finding Department of Defense-assigned IP addresses in the CI environment variables, which it attributes to sister companies rather than direct involvement. No CVE was assigned. - Comments: HN commenters note that build tools exporting
process.env into client bundles is a recurring leak pattern, and that firmware extraction plus automated secret scanning makes such leaks trivial to find at scale. - Why it matters: A CI environment variable leaked into a frontend build can hand an attacker organization-wide source-code access, a failure mode that applies to any Vite or bundler pipeline that forwards
process.env.
send feedback on this story