Abstract

Pre-deployment secret scanning operates only on source code, never on what a production application serves. We document two exploitation chains in which Azure AD client credentials and APIM subscription keys from production JavaScript bundles enabled account takeover and mass data exposure. An authorized engagement covered approximately 2,000 enterprise web assets in one organization; 113 (5.65%) served live credentials. To quantify the shift-right gap, we built an independent Ground Truth (GT-194) of 194 secret-grade credentials through Claude Opus 4.7 extraction and manual analyst review, with the 247 LLM-extracted candidates independently validated by GPT-5.5 (Brennan-Prediger kappa = 0.676). The principal finding is structural: 13.9% of GT-194 (27 of 194) is surfaced only by manual analysis and recovered by none of the nine evaluated production scanners, a tool-agnostic blind spot the ground-truth model also misses. CryptoJS encrypted configuration separately defeats every static scanner: the credential exists only after decryption with a co-located key, reached only by runtime-aware detection. Combined coverage plateaus at 86.1%. Among the nine scanners, the best static scanner recovers 36.6% and the best runtime-aware scanner 77.8% (F1 = 0.818, McNemar p < 0.001); the ground-truth model is reported separately as a reference comparator, not an evaluated detector. On 63 of 86 secret-exposed applications (73.3%), the full Azure AD token-mint chain is co-located in one bundle, reachable from browser code. We characterize five paths by which credentials reach production undetected and present a layered runtime detection methodology and remediation framework. Recall is scoped to a single-organization Azure-heavy corpus.

Keywords

Subject

Publication details

DOI
10.1109/access.2026.3734984
Journal
Not available
Open access
Green open access

Cite this article

APA 7

Gorijala, H. (2026). Secrets That Survive Everything: Runtime Credential Exposure in Production Web Applications. https://doi.org/10.1109/access.2026.3734984

MLA 9

Gorijala, Hemanth. "Secrets That Survive Everything: Runtime Credential Exposure in Production Web Applications." https://doi.org/10.1109/access.2026.3734984.

Chicago (author–date)

Gorijala, Hemanth. 2026. "Secrets That Survive Everything: Runtime Credential Exposure in Production Web Applications." https://doi.org/10.1109/access.2026.3734984.

Harvard

Gorijala, H. (2026) 'Secrets That Survive Everything: Runtime Credential Exposure in Production Web Applications', doi:10.1109/access.2026.3734984.

Vancouver

Gorijala H. Secrets That Survive Everything: Runtime Credential Exposure in Production Web Applications. doi:10.1109/access.2026.3734984

IEEE

H. Gorijala, "Secrets That Survive Everything: Runtime Credential Exposure in Production Web Applications," doi: 10.1109/access.2026.3734984.