API keys and passwords hardcoded in script files
A network traffic study found that 282 iOS applications using AI/LLM features are leaking API keys and exposing OpenAI proxy access in plaintext network traffic - evidence that hardcoded credentials remain a systemic weakness (MITRE T1078.001). The same pattern shows up in the enterprise: Python, shell, and PowerShell scripts routinely ship with API keys, database passwords, and service tokens baked into the source, where they end up committed to repositories, copied between machines, and readable by anyone with file access. Proactive DLP scans drives and uploads for credential patterns - API key formats, password assignments, token strings - and flags or quarantines scripts that expose them before they spread. The demo uses synthetic credentials, so it is completely safe to run in any environment.
Attack Technique
Hardcoded credentials
MITRE ATT&CK
T1078.001 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗