critical
suspicious.exposed_secret_literal
- Location
- payload/200.cjs:18446
- Finding
- File appears to expose a hardcoded API secret or token.
- Evidence
apiKey: [REDACTED],
AdvisoryAudited by Static analysis on May 10, 2026.
Detected: suspicious.exposed_secret_literal, suspicious.obfuscated_code
apiKey: [REDACTED],
password: [REDACTED]
password: [REDACTED]
const data = Buffer.from(src, 'base64');