CISA Contractor Spent Six Months Treating GitHub as a Personal Dropbox
A Nightwing employee's public 'Private-CISA' repo leaked AWS GovCloud admin keys, plaintext passwords and the agency's internal build pipeline — with secret-scanning deliberately switched off.

A contractor working for the US Cybersecurity and Infrastructure Security Agency left a public GitHub repository, cheerfully named "Private-CISA," exposing administrative credentials to three AWS GovCloud accounts, plaintext logins for dozens of internal CISA systems, and the keys to the agency's internal artefact repository. The repo was created on 13 November 2025 and only taken down this past weekend after researchers escalated the matter directly to the agency.
The contractor has been identified as an employee of Nightwing, the Dulles-based government services firm spun out of Raytheon. Nightwing declined to comment.
Guillaume Valadon, a researcher at GitGuardian, flagged the exposure on 15 May after the repository owner ignored automated alerts. GitGuardian's scanners normally rely on GitHub's push protection to catch secrets before they land in public history. In this case, the commit log showed the administrator had explicitly disabled that feature.
"Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection," Valadon wrote. He added that he initially assumed the contents were fake.
Among the exposed files were one called importantAWStokens, containing the GovCloud administrative keys, and AWS-Workspace-Firefox-Passwords.csv, a Firefox password export listing credentials for internal services including LZ-DSO — short, said Philippe Caturegli, founder of the consultancy Seralys, for Landing Zone DevSecOps, CISA's secure software build environment.
Caturegli validated that the AWS keys still worked at high privilege. The artefactory credentials, he noted, would be the more interesting prize for an attacker with patience. Backdoor a package there and it ships downstream every time CISA builds something. A persistent foothold, gift-wrapped.
Many of the exposed passwords followed the format of the platform name plus the current year. (One hesitates to imagine the rotation schedule.) The pattern of commits, Caturegli said, is consistent with someone using the repo to sync files between a work laptop and a home machine, with both a CISA email address and a personal address attached to the history.
A CISA spokesperson said the agency is investigating and that "currently, there is no indication that any sensitive data was compromised." The repository was removed shortly after notification. The AWS keys, predictably, remained valid for another 48 hours.
The agency is working with roughly two-thirds of its previous headcount, following a year of buyouts and resignations under the second Trump administration. Whether the staffing picture explains anything about contractor oversight is left as an exercise for the reader.
And the GitHub account itself? Created in September 2018. Seven years of muscle memory, one disabled safety toggle, and the agency that scolds everyone else about secrets management ends up demonstrating what not to do.



