• Sources: researcher write-up, HN 49034292
  • Summary: A researcher write-up surfaced on Hacker News on 2026-07-24 describes extracting Hanwha Vision camera firmware, then finding a GitHub token duplicated across roughly 30 files in the extracted root filesystem. The author states the token held admin privileges on hundreds of repositories in the vendor's GitHub organization. The stated cause is the camera's Vite build for the web UI writing the entire CI job environment into compiled files, including a GITHUB_NPM_TOKEN variable alongside npm, Kubernetes, and Docker environment entries. To get at the image, the author reports the inner firmware archive is AES-encrypted with a key XOR-obfuscated against a static table inside a fwupgrader binary, reconstructed at runtime and passed to the openssl CLI, and that the key is shared across the model line. No specific camera model numbers or firmware build identifiers were resolved this run, so the affected models and versions are not yet known here. The author reports downloading roughly 500 firmware images, extracting about 62% of them, and finding the same token in three. Hanwha responded within 12 hours and revoked the token. Environment variables in the dump also carried IP addresses in US Department of Defense space, which the author explicitly labels as speculation.
  • Why it matters: Writing process.env into a front-end bundle is a routine build-configuration mistake, and here it moved an organization-wide GitHub admin credential into shipped firmware and possibly onto the wire to anyone loading the camera admin UI.
  • Follow-up: Watch for a Hanwha statement on the exposure window and on whether the token was ever served to browsers, and for whether the shared firmware decryption key is rotated.

send feedback on this story