{
  "version": 1,
  "event_id": "evt_b7575ea8cf790c1a",
  "url": "https://xiyu.news/events/evt_b7575ea8cf790c1a/",
  "json": "https://xiyu.news/api/events/evt_b7575ea8cf790c1a.json",
  "type": "security_incident",
  "status": "monitoring",
  "category": "technology",
  "title": {
    "zh": "Strix 智能体借泄露令牌拿到 Baseten 生产环境 GitHub 管理员权限",
    "en": "We got admin access to Baseten's production GitHub in 25 minutes"
  },
  "current_state": {
    "zh": "安全公司 Strix 披露，其 AI 渗透测试智能体在 Harbor 容器镜像仓库中一张公开可访问的 Baseten 镜像的 Docker 构建历史里，发现了一个仍然有效的 \"basetenbot\" GitHub 个人访问令牌。该令牌对 Baseten 的主产品仓库、用于驱动其集群的 GitOps 仓库以及 Homebrew tap 拥有管理员和推送权限，另外还对若干私有仓库（包括按客户划分的仓库）拥有读写权限。Baseten 已确认该问题，将 Harbor 项目改为私有、轮换了该令牌，并表示日志显示该凭据从未被利用，也没有客户数据泄露。\n\n这一事件表明，只要有一个密钥泄漏进 CI/CD 构建产物，就可能暴露一家 AI 基础设施厂商的整套生产工具链，包括部署其集群的 GitOps 流水线以及按客户划分的仓库。它同时是\"智能体化渗透测试\"的早期真实案例：一个自动化智能体发现并上报了一条长期躺在公开镜像仓库中无人注意的凭据链，这也引发了业界关于还有多少同类暴露尚未被发现的讨论。\n\n根据披露的时间线，Strix 于 7 月 13 日晚 11:10 上报了仍有效的令牌、公开的 Harbor 项目以及相关仓库权限；Baseten 次日早晨将 Harbor 项目转为私有，但 Strix 指出该令牌仍然可用，随后 Baseten 安全团队将该问题确认为严重级别，并于 7 月 14 日下午 4:34 完成令牌轮换，同时要求 Strix 安全删除其已拉取的镜像。该令牌是从 Docker 构建历史中恢复的，而非来自源代码；Strix 的渗透测试工具为开源项目，其 GitHub 仓库已获得数万颗星，并可与兼容 SKILL.md 的编码智能体集成。",
    "en": "Strix.ai reports that its AI pen-testing agent found an exposed Baseten GitHub admin token granting access to production, GitOps, and customer repositories, prompting Baseten to rotate the token and make the affected project private."
  },
  "first_seen_at": "2026-09-15T23:01:44.823706+00:00",
  "last_updated_at": "2026-09-15T23:01:44.823706+00:00",
  "last_material_change_at": "2026-09-15T23:01:44.823706+00:00",
  "confidence": 0.75,
  "updates_count": 1,
  "sources_count": 1,
  "entities": [
    "baseten",
    "github"
  ],
  "identifiers": [],
  "topics": [
    "devtools",
    "disclosure",
    "github"
  ],
  "updates": [
    {
      "update_id": "upd_e861811cf03f6b1c",
      "event_id": "evt_b7575ea8cf790c1a",
      "occurred_at": "2026-09-15T18:11:24Z",
      "published_at": "2026-09-15T18:11:24Z",
      "first_seen_at": "2026-09-15T23:01:44.823706Z",
      "time_precision": "published",
      "update_type": "initial",
      "material_change": true,
      "title_zh": "Strix 智能体借泄露令牌拿到 Baseten 生产环境 GitHub 管理员权限",
      "title_en": "We got admin access to Baseten's production GitHub in 25 minutes",
      "what_changed_zh": "安全公司 Strix 披露，其 AI 渗透测试智能体在 Harbor 容器镜像仓库中一张公开可访问的 Baseten 镜像的 Docker 构建历史里，发现了一个仍然有效的 \"basetenbot\" GitHub 个人访问令牌。该令牌对 Baseten 的主产品仓库、用于驱动其集群的 GitOps 仓库以及 Homebrew tap 拥有管理员和推送权限，另外还对若干私有仓库（包括按客户划分的仓库）拥有读写权限。Baseten 已确认该问题，将 Harbor 项目改为私有、轮换了该令牌，并表示日志显示该凭据从未被利用，也没有客户数据泄露。\n\n这一事件表明，只要有一个密钥泄漏进 CI/CD 构建产物，就可能暴露一家 AI 基础设施厂商的整套生产工具链，包括部署其集群的 GitOps 流水线以及按客户划分的仓库。它同时是\"智能体化渗透测试\"的早期真实案例：一个自动化智能体发现并上报了一条长期躺在公开镜像仓库中无人注意的凭据链，这也引发了业界关于还有多少同类暴露尚未被发现的讨论。\n\n根据披露的时间线，Strix 于 7 月 13 日晚 11:10 上报了仍有效的令牌、公开的 Harbor 项目以及相关仓库权限；Baseten 次日早晨将 Harbor 项目转为私有，但 Strix 指出该令牌仍然可用，随后 Baseten 安全团队将该问题确认为严重级别，并于 7 月 14 日下午 4:34 完成令牌轮换，同时要求 Strix 安全删除其已拉取的镜像。该令牌是从 Docker 构建历史中恢复的，而非来自源代码；Strix 的渗透测试工具为开源项目，其 GitHub 仓库已获得数万颗星，并可与兼容 SKILL.md 的编码智能体集成。",
      "what_changed_en": "Strix.ai reports that its AI pen-testing agent found an exposed Baseten GitHub admin token granting access to production, GitOps, and customer repositories, prompting Baseten to rotate the token and make the affected project private.",
      "current_state_zh": "安全公司 Strix 披露，其 AI 渗透测试智能体在 Harbor 容器镜像仓库中一张公开可访问的 Baseten 镜像的 Docker 构建历史里，发现了一个仍然有效的 \"basetenbot\" GitHub 个人访问令牌。该令牌对 Baseten 的主产品仓库、用于驱动其集群的 GitOps 仓库以及 Homebrew tap 拥有管理员和推送权限，另外还对若干私有仓库（包括按客户划分的仓库）拥有读写权限。Baseten 已确认该问题，将 Harbor 项目改为私有、轮换了该令牌，并表示日志显示该凭据从未被利用，也没有客户数据泄露。\n\n这一事件表明，只要有一个密钥泄漏进 CI/CD 构建产物，就可能暴露一家 AI 基础设施厂商的整套生产工具链，包括部署其集群的 GitOps 流水线以及按客户划分的仓库。它同时是\"智能体化渗透测试\"的早期真实案例：一个自动化智能体发现并上报了一条长期躺在公开镜像仓库中无人注意的凭据链，这也引发了业界关于还有多少同类暴露尚未被发现的讨论。\n\n根据披露的时间线，Strix 于 7 月 13 日晚 11:10 上报了仍有效的令牌、公开的 Harbor 项目以及相关仓库权限；Baseten 次日早晨将 Harbor 项目转为私有，但 Strix 指出该令牌仍然可用，随后 Baseten 安全团队将该问题确认为严重级别，并于 7 月 14 日下午 4:34 完成令牌轮换，同时要求 Strix 安全删除其已拉取的镜像。该令牌是从 Docker 构建历史中恢复的，而非来自源代码；Strix 的渗透测试工具为开源项目，其 GitHub 仓库已获得数万颗星，并可与兼容 SKILL.md 的编码智能体集成。",
      "current_state_en": "Strix.ai reports that its AI pen-testing agent found an exposed Baseten GitHub admin token granting access to production, GitOps, and customer repositories, prompting Baseten to rotate the token and make the affected project private.",
      "detailed_summary_zh": "Strix.ai reports that its AI pen-testing agent found an exposed Baseten GitHub admin token granting access to production, GitOps, and customer repositories, prompting Baseten to rotate the token and make the affected project private.",
      "detailed_summary_en": "Strix.ai reports that its AI pen-testing agent found an exposed Baseten GitHub admin token granting access to production, GitOps, and customer repositories, prompting Baseten to rotate the token and make the affected project private.",
      "background_zh": "GitHub 个人访问令牌（PAT）相当于用于 API 和 Git 操作的密码，一旦权限范围较广的 PAT 泄露，攻击者便可读取和修改代码、CI 配置以及部署工具链。Docker 镜像按层构建，构建过程中被复制或引用的密钥（例如通过 ARG、ENV 或复制文件）可能残留在镜像历史中，因此拉取并检查镜像就可能发现凭据——此前已有报告记录过数千个 Docker Hub 镜像大规模泄露凭据的同类情况。Baseten 是一家 C 轮公司，提供企业用于部署和运行私有模型的 AI 推理平台，因此其部署相关仓库在运营上高度敏感。",
      "background_en": "A GitHub personal access token (PAT) is a credential that acts like a password for API and Git operations, and a leaked PAT with broad scopes lets an attacker read and modify code, CI configuration, and deployment tooling. Docker images are built in layers, and secrets that are copied or referenced during a build (for example via ARG, ENV, or copied files) can persist inside the image history, so pulling and inspecting an image can reveal credentials — a pattern previously documented at scale across thousands of Docker Hub images. Baseten is a Series C company offering an AI inference platform that enterprises use to deploy and run proprietary models, which makes its deployment repositories operationally sensitive.",
      "community_discussion_zh": "Hacker News 讨论帖（196 分、106 条评论）情绪分歧明显：有人称赞 Baseten 响应迅速、处置流程记录清晰，但也有不少人批评 Strix.ai 实际上是把真实厂商当作营销素材，并且在更克制的披露方式已足够的情况下点名了受害方。还有人质疑此类探测的合法性，将其比作撬开邻居家门，同时也承认这个故事确实让他们对 Strix 的工具产生了评估兴趣。",
      "community_discussion_en": "The Hacker News thread (196 points, 106 comments) shows mixed sentiment: commenters credit Baseten for a fast, well-documented remediation, but several criticize Strix.ai for effectively using a real vendor as a marketing campaign and for naming the victim when a simpler disclosure would have sufficed. Others question the legality of the probing, compare it to breaking into a neighbor's house, and note that the story nonetheless makes them curious enough to evaluate Strix's tooling.",
      "market_impact_zh": "",
      "market_impact_en": "",
      "importance_score": 7.5,
      "references": [
        {
          "url": "https://news.ycombinator.com/item?id=49716476",
          "title": "Community discussion"
        },
        {
          "url": "https://www.baseten.co/",
          "title": "Inference Platform: Deploy AI models in production | Baseten"
        },
        {
          "url": "https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens",
          "title": "Managing your personal access tokens - GitHub Docs"
        },
        {
          "url": "https://nhimg.org/massive-docker-hub-leak-10000-images-expose-secrets-and-auth-keys",
          "title": "Massive Docker Hub Leak: 10,000+ Images Expose Secrets and Auth..."
        },
        {
          "url": "https://goharbor.io/",
          "title": "Harbor"
        },
        {
          "url": "https://www.strix.ai/ai-pentest-agent",
          "title": "AI Pentest Agent: An Agent That Exploits and Patches | Strix"
        }
      ],
      "confidence": 0.75,
      "story_ids": [
        "hackernews:story:49716476"
      ],
      "sources": [
        {
          "url": "https://www.strix.ai/blog/baseten-harbor-github-pat-takeover",
          "label": "bearsyankees",
          "source_type": "hackernews",
          "official": false
        }
      ]
    }
  ]
}
