By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys
Computing

Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys

News Room
Last updated: 2025/11/25 at 12:33 PM
News Room Published 25 November 2025
Share
Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys
SHARE

Nov 25, 2025Ravie LakshmananData Exposure / Cloud Security

New research has found that organizations in various sensitive sectors, including governments, telecoms, and critical infrastructure, are pasting passwords and credentials into online tools like JSONformatter and CodeBeautify that are used to format and validate code.

Cybersecurity company watchTowr Labs said it captured a dataset of over 80,000 files on these sites, uncovering thousands of usernames, passwords, repository authentication keys, Active Directory credentials, database credentials, FTP credentials, cloud environment keys, LDAP configuration information, helpdesk API keys, meeting room API keys, SSH session recordings, and all kinds of personal information.

This includes five years of historical JSONFormatter content and one year of historical CodeBeautify content, totalling over 5GB worth of enriched, annotated JSON data.

DFIR Retainer Services

Organizations impacted by the leak span critical national infrastructure, government, finance, insurance, banking, technology, retail, aerospace, telecommunications, healthcare, education, travel, and, ironically, cybersecurity sectors.

“These tools are extremely popular, often appearing near the top of search results for terms like ‘JSON beautify’ and ‘best place to paste secrets’ (probably, unproven) — and used by a wide variety of organizations, organisms, developers, and administrators in both enterprise environments and for personal projects,” security researcher Jake Knott said in a report shared with The Hacker News.

Both tools also offer the ability to save a formatted JSON structure or code, turning it into a semi-permanent, shareable link with others – effectively allowing anyone with access to the URL to access the data.

As it happens, the sites not only provide a handy Recent Links page to list all recently saved links, but also follow a predictable URL format for the shareable link, thereby making it easier for a bad actor to retrieve all URLs using a simple crawler –

  • https://jsonformatter.org/{id-here}
  • https://jsonformatter.org/{formatter-type}/{id-here}
  • https://codebeautify.org/{formatter-type}/{id-here}

Some examples of leaked information include Jenkins secrets, a cybersecurity company exposing encrypted credentials for sensitive configuration files, Know Your Customer (KYC) information associated with a bank, a major financial exchange’s AWS credentials linked to Splunk, and Active Directory credentials for a bank.

CIS Build Kits

To make matters worse, the company said it uploaded fake AWS access keys to one of these tools, and found bad actors attempting to abuse them 48 hours after it was saved. This indicates that valuable information exposed through these sources is being scraped by other parties and tested, posing severe risks.

“Mostly because someone is already exploiting it, and this is all really, really stupid,” Knott said. “We don’t need more AI-driven agentic agent platforms; we need fewer critical organizations pasting credentials into random websites.”

When checked by The Hacker News, both JSONFormatter and CodeBeautify have temporarily disabled the save functionality, claiming they are “working on to make it better” and implementing “enhanced NSFW (Not Safe For Work) content prevention measures.”

watchTowr said that the save functionality was disabled by these sites likely in response to the research. “We suspect this change occurred in September in response to communication from a number of the affected organizations we alerted,” it added.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Black Friday Week’s Best Tech Deals: Save Some Serious Cash on Top Electronics from Apple, Bose, HP, Samsung, and More Black Friday Week’s Best Tech Deals: Save Some Serious Cash on Top Electronics from Apple, Bose, HP, Samsung, and More
Next Article They relied on marijuana to get through the day. But then days felt impossible without it
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

AMDGPU Driver Lacks HDMI 2.1 While AMD-Xilinx Driver Has Some HDMI 2.1 Support
AMDGPU Driver Lacks HDMI 2.1 While AMD-Xilinx Driver Has Some HDMI 2.1 Support
Computing
Google Launches Agent Development Kit for Go
Google Launches Agent Development Kit for Go
News
M5 Apple Vision Pro vs. Steam Frame: Spatial computing vs. VR gaming
M5 Apple Vision Pro vs. Steam Frame: Spatial computing vs. VR gaming
News
Amazon Urges Staff to Use In-House Kiro Over Rival AI Coding Tools | HackerNoon
Amazon Urges Staff to Use In-House Kiro Over Rival AI Coding Tools | HackerNoon
Computing

You Might also Like

AMDGPU Driver Lacks HDMI 2.1 While AMD-Xilinx Driver Has Some HDMI 2.1 Support
Computing

AMDGPU Driver Lacks HDMI 2.1 While AMD-Xilinx Driver Has Some HDMI 2.1 Support

3 Min Read
Amazon Urges Staff to Use In-House Kiro Over Rival AI Coding Tools | HackerNoon
Computing

Amazon Urges Staff to Use In-House Kiro Over Rival AI Coding Tools | HackerNoon

1 Min Read
What the World Series Means to Me, A Daughter of Latin American Immigrants – Knock LA
Computing

What the World Series Means to Me, A Daughter of Latin American Immigrants – Knock LA

8 Min Read
Singapore Orders Apple, Google to Block Gov’t Spoofing on Messaging Apps | HackerNoon
Computing

Singapore Orders Apple, Google to Block Gov’t Spoofing on Messaging Apps | HackerNoon

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?