Developers now run coding agents, MCP servers, and IDE extensions on their laptops. Each tool reads files with their access. Security teams watch these machines with EDR, but EDR tools only see the operating system, not the tools developers run on it.
A large enterprise ran a mature security program with commercial EDR on every developer laptop. Their security team installed Boost Developer Endpoint Protection on 1,386 machines expecting to find nothing (except the test packages they had planted themselves).
Boost Developer Endpoint Protection counted 41,660 exposed secrets across the 1,386 machines, roughly 30 per laptop. Developers left API keys, tokens, and credentials in plaintext. Anything running on the machine could read them.
Never expires, broad access. SSH private keys, AWS secret keys.
Long-lived, scoped, revocable. GitHub PATs, npm publish tokens.
Rotatable, or lifetime unclear. JWTs, OAuth access tokens.
Self-expires in minutes or hours. AWS STS, GitHub App tokens.
Only 2.9% of the 41,660 expired on their own. 89.6% were rated High or Critical, including credentials that can open cloud infrastructure, source control, and production services.
Boost Developer Endpoint Protection found active malware on five machines. These counts exclude every detection tied to the team's own planted test packages. One developer was doing daily work on a laptop with six separate infections.
The security team ran EDR on all five laptops and got no alerts. Nobody misconfigured anything. Attackers shipped this malware through the dependency channel, and the engineers who built EDR never designed it to watch that layer.
Five devs had malware-infected machines, and they'd left secrets for attackers to find: 398 of them, or about 3x more per machine than average. Malware on those machines had the same file access they did.
Boost Developer Endpoint Protection found two Anthropic Admin API keys among the Critical secrets, and OpenAI keys on the infected machines. Whoever holds an admin key can create new keys and manage the whole account.
These credentials didn't exist three years ago. Developers already store them like everything else: in plaintext, on laptops.
Boost Developer Endpoint Protection found all of this on 1,386 laptops in a single deployment. EDR was running on every one of these machines, but it couldn't see this layer of the attack surface.
Reach out for a demo at boostsecurity.io and we'll show you what's been hiding beyond your EDR's reach.
GET A FREE SCAN →Try Dazio, our free-forever tool for developers who want to protect themselves from the security risks of agentic coding tools.
It takes two minutes to find out if your machine is already infected, and your data never leaves your device.
SCAN MY MACHINE FREE →The AI-Native SDLC Defense Platform. Securing the code, the agent, and the endpoint - before commit.
Montreal, Canada
© 2026 BoostSecurity Inc. All rights reserved.