critical
suspicious.env_credential_access
- Location
- dist/bundle.js:1
- Finding
- Environment variable access combined with network send.
- Evidence
delete process.env.ANCHOR_WALLET;
AdvisoryAudited by Static analysis on May 13, 2026.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal, suspicious.potential_exfiltration
delete process.env.ANCHOR_WALLET;
const secretKey = [REDACTED](seed);
const payer = web3_js_1.Keypair.fromSecretKey(buffer_1.Buffer.from(JSON.parse(require("fs").readFileSync(process2.env.ANCHOR_WALLET, {