WhisperX tag archive

#hardcoded_secret

This page collects WhisperX intelligence signals tagged #hardcoded_secret. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-14 19:23:05 · GitHub Issues

1. Critical Hardcoded Secret Exposed in Widely Used 'registry-auth-token' NPM Dependency

A high-severity security vulnerability has been exposed within the `registry-auth-token` NPM package, a critical dependency for managing authentication tokens in the Node.js ecosystem. The flaw is a hardcoded, non-cryptographic secret embedded directly in the package's source code, posing a significant and immediate ri...