Thousands of Passwords Exposed via Popular JSON Formatter Tools

Organizations Leak Sensitive Credentials Through Online Code Formatting Tools, Leading to Active Exploitation and Temporary Feature Disabling

  • Organizations across sensitive sectors are exposing credentials by pasting them into online code formatting tools.
  • A dataset of over 80,000 files on JSONformatter and CodeBeautify revealed thousands of leaked credentials and personal data.
  • The shareable link feature of these tools makes sensitive information accessible and easy to scrape by malicious actors.
  • Fake AWS keys uploaded to these platforms were tested by attackers within 48 hours, showing active exploitation of leaked data.
  • Both tools have temporarily disabled the save function, likely responding to security concerns raised by affected organizations.

New research reveals that organizations in critical sectors such as government, telecommunications, and infrastructure have been exposing sensitive credentials by pasting them into online code formatting and validation tools. The Cybersecurity firm watchTowr Labs collected a dataset of over 80,000 files from platforms including JSONformatter and CodeBeautify, uncovering a wide range of leaked data like usernames, passwords, repository keys, database access credentials, and API keys.

- Advertisement -

This data spans five years of JSONformatter content and one year from CodeBeautify, totaling more than 5 gigabytes of annotated JSON files. Affected sectors include finance, healthcare, aerospace, education, retail, and cybersecurity, among others. Security researcher Jake Knott explained that these tools are popular and often ranked high in search engine results, leading many organizations and developers to use them for formatting code that sometimes contains sensitive information, as stated here.

Both services allow users to save formatted code as shareable links, which can be accessed by anyone with the URL. These links follow predictable patterns (e.g., https://jsonformatter.org/{id} or https://codebeautify.org/{formatter-type}/{id}), making it possible for malicious actors to scrape exposed data using automated crawlers. Examples of leaked information include Jenkins secrets, encrypted credentials, Know Your Customer (KYC) details from banks, AWS credentials linked to a financial exchange’s monitoring tools, and Active Directory credentials for banking institutions.

watchTowr Labs conducted tests by uploading fake AWS keys, observing that these were targeted by attackers within 48 hours of being posted. This demonstrated active scraping and exploitation of exposed credentials. Knott emphasized the severity, stating, “Mostly because someone is already exploiting it, and this is all really, really stupid.”

In response to these findings, both JSONformatter and CodeBeautify have temporarily disabled the save functionality, reporting they are working on improvements and enhanced content prevention measures. watchTowr Labs suspects this action followed September communications with impacted organizations, as detailed above.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Russia Scraps Single BRICS Currency Plan for Summit

Russia has clarified that a BRICS common currency is not on the agenda for...

Schiff Predicts Bitcoin Support Near $10,000 in Swipe at Saylor

Gold proponent Peter Schiff critiqued Michael Saylor's debt-refinancing plan for buying more Bitcoin if...

SBF’s Google Doc Strategy: A Transparent Grab for Pardon

From his prison cell in early 2026, Sam Bankman-Fried continues broadcasting calculated messages that...

Consensus Hong Kong draws 11K; Trump-linked project unveils plans

Consensus Hong Kong drew over 11,000 attendees, focusing on institutional topics and developer challenges.World...

GLM-5 Launch Sparks Surge in Chinese AI Stocks

Hong Kong-listed Zhipu AI launched its GLM-5 AI model on February 11, 2026.The launch...

Must Read

Top 10 Best DeFi Tokens to Invest in 2022

Decentralized Finance (Defi), is one of the most talked-about topics in the crypto space alongside NFTs. So if you want to know the best...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!