logo

Code beautifiers expose credentials from banks, govt, tech orgs

ID: c7681ec2-e6fe-5f3e-80cc-17cdbfba307b

STIX ID: report--c7681ec2-e6fe-5f3e-80cc-17cdbfba307b

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-11-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers from watchTowr discovered that the 'Recent Links' feature on JSONFormatter and CodeBeautify publicly exposed over 80,000 user pastes (5+ GB) containing sensitive data—including Active Directory credentials, cloud/AWS keys, private keys, API tokens, CI/CD secrets, and large amounts of PII—allowing easy scraping by attackers; honeypot Canarytokens showed malicious access attempts even after links expired and many affected organizations did not fully remediate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.