BOOST SECURITY LABS · FIELD REPORT

What 1,386 Developer Laptops Were Hiding

Developers now run coding agents, MCP servers, and IDE extensions on their laptops. Each tool reads files with their access. Security teams watch these machines with EDR, but EDR tools only see the operating system, not the tools developers run on it.

A large enterprise ran a mature security program with commercial EDR on every developer laptop. Their security team installed Boost Developer Endpoint Protection on 1,386 machines expecting to find nothing (except the test packages they had planted themselves).

Boost Developer Endpoint Protection began returning findings within minutes.
02 · SECRETS

The average developer laptop held 30 exposed secrets

41,660
exposed secrets found
30per laptop

Boost Developer Endpoint Protection counted 41,660 exposed secrets across the 1,386 machines, roughly 30 per laptop. Developers left API keys, tokens, and credentials in plaintext. Anything running on the machine could read them.

9 in 10 exposed secrets were High or Critical.
CRITICAL
1,030
HIGH
36,287
MEDIUM
3,138
LOW
1,205
CRITICAL

Never expires, broad access. SSH private keys, AWS secret keys.

HIGH

Long-lived, scoped, revocable. GitHub PATs, npm publish tokens.

MEDIUM

Rotatable, or lifetime unclear. JWTs, OAuth access tokens.

LOW

Self-expires in minutes or hours. AWS STS, GitHub App tokens.

Only 2.9% of the 41,660 expired on their own. 89.6% were rated High or Critical, including credentials that can open cloud infrastructure, source control, and production services.

03 · MALWARE

Malware ran on 5 machines despite EDR

5 machines with active malware (of 1,386 scanned).
MALWARE PRESENT (5)
PLANTED TEST PACKAGE (8)
CLEAN (1,373)

Boost Developer Endpoint Protection found active malware on five machines. These counts exclude every detection tied to the team's own planted test packages. One developer was doing daily work on a laptop with six separate infections.

The security team ran EDR on all five laptops and got no alerts. Nobody misconfigured anything. Attackers shipped this malware through the dependency channel, and the engineers who built EDR never designed it to watch that layer.

04 · OVERLAP

Malware-infected machines had nearly 3x the secrets

FLEET AVERAGE
30 secrets per machine
MACHINES WITH MALWARE
80 secrets per machine

Five devs had malware-infected machines, and they'd left secrets for attackers to find: 398 of them, or about 3x more per machine than average. Malware on those machines had the same file access they did.

The two most critical secrets:
Anthropic admin keys
sk-ant-admin-••••••••
found in plaintext on a developer laptop.

Boost Developer Endpoint Protection found two Anthropic Admin API keys among the Critical secrets, and OpenAI keys on the infected machines. Whoever holds an admin key can create new keys and manage the whole account.

These credentials didn't exist three years ago. Developers already store them like everything else: in plaintext, on laptops.

FOUND ON THE SAME DEVICES AS THE MALWARE
HashiCorp Vault
one engineer's login, every runtime secret behind it
AWS
an engineer's infrastructure keys
OpenAI
an API key that bills to the company

One company found 41,660 secrets and 5 infected machines. What would you find?

30
exposed secrets per developer laptop
1 in 277
Developer machines with active malware (that EDR didn't catch)
80
secrets per infected machine; fleet average 30

Boost Developer Endpoint Protection found all of this on 1,386 laptops in a single deployment. EDR was running on every one of these machines, but it couldn't see this layer of the attack surface.

Talk to us about a free scan of your developers' devices.

Reach out for a demo at boostsecurity.io and we'll show you what's been hiding beyond your EDR's reach.

GET A FREE SCAN →
Dazio by Boost Security

Wondering what's on your laptop?

Try Dazio, our free-forever tool for developers who want to protect themselves from the security risks of agentic coding tools.

It takes two minutes to find out if your machine is already infected, and your data never leaves your device.

SCAN MY MACHINE FREE →