I messed up things. I am building an opensource package to connect multiple S3 compatible services like cloudflare r2, digitalocean etc. so when testing I used original API keys and I totally forgot to remove things and just did npm publish. and then I noticed I have exposed keys. I just deleted the whole package and re-upload it with another name with proper checking. now here comes the shocking story AWS somehow noticed it and limited my access and threatening to stop our production server. I know everything is safe but still I have to convince AWS support. however if anybody curious about the package it's called multibucket https://www.npmjs.com/package/multibucket
Download the medial app to read full posts, comements and news.