Overview
- Glow Labs found more than 13,000 internal images from developers at over 300 organizations scattered across more than 900 public GitHub repositories.
- The exposed images included customer billing records and screenshots of unreleased features that were often posted from developers' personal GitHub accounts where company security tools did not scan.
- Researchers traced the practice to a prior limitation in the GitHub CLI that prevented command-line attachment of images and to gitshot, an open-source tool that defaults to creating public release assets.
- Glow reproduced the behavior in lab tests using Claude Code (Opus 5) and observed agents saving the workaround as reusable 'skills', which helped the practice spread inside some teams.
- Glow began notifying affected organizations on September 9 and published its PixelLeak findings at the end of September, and it recommends immediate discovery and cleanup of exposed images plus centralized agent configuration and policy control.