Code beautifiers expose credentials from banks, govt, tech orgs
ID: c7681ec2-e6fe-5f3e-80cc-17cdbfba307b
STIX ID: report--c7681ec2-e6fe-5f3e-80cc-17cdbfba307b
Feed Name: Bleeping Computer
Threat Score
Researchers from watchTowr discovered that the 'Recent Links' feature on JSONFormatter and CodeBeautify publicly exposed over 80,000 user pastes (5+ GB) containing sensitive data—including Active Directory credentials, cloud/AWS keys, private keys, API tokens, CI/CD secrets, and large amounts of PII—allowing easy scraping by attackers; honeypot Canarytokens showed malicious access attempts even after links expired and many affected organizations did not fully remediate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
