Skip to content

[PKGuardian] Possible leaked secret detected in MystenLabs/sui-packages #16

@pkguardian-4

Description

@pkguardian-4

Leaked Secret Detected

PKGuardian detected what appears to be a EVM Private Key (0x) in a recent commit.

Field Value
Commit 202d48adb2e398c65283b6094f3620d63f12acf4
File packages/mainnet/0x3b/a5d3cc7847900db623210b818d88aa465b4d523d170e91f090fd0745af86e3/decompiled_modules/cetus_clmm.move
Secret (redacted) 6fedc46981bdbc93eb7221cf5b263be1f4b36a62892c89cf0883eeba80a63790

What to do

  1. Rotate the key immediately. Even if you remove the commit, it may already be cached by bots.
  2. Revoke the old key in the corresponding service.
  3. Consider using a .gitignore or a secrets manager to prevent future leaks.
  4. Use git filter-repo or BFG to scrub the key from history if needed.

This issue was opened automatically by PKGuardian - a public GitHub push secret scanner.
If this is a false positive, feel free to close this issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions