BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Thousands of Passwords Exposed via Popular JSON Formatter Tools

Organizations Leak Sensitive Credentials Through Online Code Formatting Tools, Leading to Active Exploitation and Temporary Feature Disabling

  • Organizations across sensitive sectors are exposing credentials by pasting them into online code formatting tools.
  • A dataset of over 80,000 files on JSONformatter and CodeBeautify revealed thousands of leaked credentials and personal data.
  • The shareable link feature of these tools makes sensitive information accessible and easy to scrape by malicious actors.
  • Fake AWS keys uploaded to these platforms were tested by attackers within 48 hours, showing active exploitation of leaked data.
  • Both tools have temporarily disabled the save function, likely responding to security concerns raised by affected organizations.

New research reveals that organizations in critical sectors such as government, telecommunications, and infrastructure have been exposing sensitive credentials by pasting them into online code formatting and validation tools. The Cybersecurity firm watchTowr Labs collected a dataset of over 80,000 files from platforms including JSONformatter and CodeBeautify, uncovering a wide range of leaked data like usernames, passwords, repository keys, database access credentials, and API keys.

- Advertisement -

This data spans five years of JSONformatter content and one year from CodeBeautify, totaling more than 5 gigabytes of annotated JSON files. Affected sectors include finance, healthcare, aerospace, education, retail, and cybersecurity, among others. Security researcher Jake Knott explained that these tools are popular and often ranked high in search engine results, leading many organizations and developers to use them for formatting code that sometimes contains sensitive information, as stated here.

Both services allow users to save formatted code as shareable links, which can be accessed by anyone with the URL. These links follow predictable patterns (e.g., https://jsonformatter.org/{id} or https://codebeautify.org/{formatter-type}/{id}), making it possible for malicious actors to scrape exposed data using automated crawlers. Examples of leaked information include Jenkins secrets, encrypted credentials, Know Your Customer (KYC) details from banks, AWS credentials linked to a financial exchange’s monitoring tools, and Active Directory credentials for banking institutions.

watchTowr Labs conducted tests by uploading fake AWS keys, observing that these were targeted by attackers within 48 hours of being posted. This demonstrated active scraping and exploitation of exposed credentials. Knott emphasized the severity, stating, “Mostly because someone is already exploiting it, and this is all really, really stupid.”

In response to these findings, both JSONformatter and CodeBeautify have temporarily disabled the save functionality, reporting they are working on improvements and enhanced content prevention measures. watchTowr Labs suspects this action followed September communications with impacted organizations, as detailed above.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

North Korea arrests crypto laundering bank hackers

North Korean authorities arrested a group of former state cyber operators and IT specialists...

Morgan Stanley hikes Apple stock target to $364, sees 13% ROI

Apple stock opened Friday at $321 after a 1.30% decline, as tech stocks face...

Peter Schiff warns Bitcoin break below $50,000 could trigger crash to $20,000

Peter Schiff warned that Strategy's Bitcoin-driven capital structure promotes “excessive speculation” and could leave...

US Spot Ethereum ETFs See $70.6M Outflow, Ending 5-Day Inflow Streak

US spot Ethereum ETFs ended a five-day inflow streak with $70.62 million in net...

Solana drops to $73.53 as market risk appetite wanes

Solana's SOL token dropped 3.8% to $73.53 on July 24 as broader crypto markets...

Must Read

7 Best Audiobooks on Cybersecurity

Cybersecurity has become an essential topic in our increasingly digital world. As technology evolves and becomes more integrated into our daily lives, the importance...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading