critical
suspicious.env_credential_access
- Location
- dist/index.cjs:153
- Finding
- Environment variable access combined with network send.
- Evidence
var env = process.env;
AdvisoryAudited by Static analysis on May 13, 2026.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal, suspicious.obfuscated_code
var env = process.env;
var env = process.env;
accessToken: [REDACTED],
const response = await http2.post(url, data, { headers: { Authorization: [REDACTED] } });accessToken: [REDACTED],
req.end(Buffer.from(jsonStringify(options, this.options.replacer), "utf8"));
req.end(Buffer.from(jsonStringify(options, this.options.replacer), "utf8"));