sci-download
Audited by Socket on Aug 16, 2026
2 alerts found:
Anomalyx2This code is primarily a local configuration/credential manager that reads and writes plaintext credentials/config files and derives WebVPN host/crypto parameters from local JSON. No direct malware behavior (e.g., network exfiltration, shell execution, or overt backdoors) is present in the shown fragment. The dominant security risk is the supply-chain/local-tampering exposure created by dynamically executing a sibling Python file (_shared/env_config.py) via exec_module(). Additional concerns are hardcoded WebVPN crypto defaults and persistent plaintext storage of API keys/tokens in a user-writable .env file.
This fragment is static JSON configuration with no executable logic, so it does not directly demonstrate malware behavior. However, it embeds repeated hardcoded symmetric crypto material (crypto_key and crypto_iv) using a single constant across multiple entries, including a static IV, which is a serious cryptographic/secret-handling design risk. Impact depends entirely on how downstream code consumes these fields; nevertheless, the embedded secrets and lack of cryptographic context warrant urgent review/rotation and verification of the consuming crypto implementation.