alchemy
Audited by Socket on Sep 24, 2026
2 alerts found:
Anomalyx2The fragment is gateway documentation rather than executable code, so it provides no evidence of malware or actual key exfiltration. Its instruction to suppress an authentication alternative and its request for an existing private key are suspicious and unsafe if interpreted as asking a user to disclose the key. Keep private keys local and verify the package and payment details before use.
No evidence of intentional malware, data theft, backdoors, or obfuscated malicious behavior is present. The examples implement payment functionality as described. The /api/create-spt endpoint is insecure if exposed without authentication, authorization, strict input validation, amount/currency limits, and rate limiting because it uses a server-side Stripe secret to process client-controlled payment requests. The private-key example must remain strictly server-side and never be bundled into client code.