{"id":89272,"date":"2025-11-27T07:43:31","date_gmt":"2025-11-27T05:43:31","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=89272"},"modified":"2025-11-27T07:43:36","modified_gmt":"2025-11-27T05:43:36","slug":"code-formatting-sites-leak-user-secrets-and-credentials","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/newswire\/business\/89272\/code-formatting-sites-leak-user-secrets-and-credentials\/","title":{"rendered":"Code Formatting Sites Leak User Secrets and Credentials"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\"><summary>\u25bc Summary<\/summary>\n<p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; JSONFormatter and CodeBeautify are exposing sensitive user data like credentials and API keys through their public and predictable shareable links.<br>&#8211; Researchers found over 80,000 saved entries containing critical information from various sectors, including government, finance, and healthcare.<br>&#8211; Malicious actors are actively scraping these sites for credentials, as confirmed by canary token misuse within 48 hours.<br>&#8211; Attempts to warn affected organizations were largely unacknowledged, and similar risks likely exist on other code formatting websites.<br>&#8211; Users should avoid pasting sensitive data into online tools, as anything entered can be stored and potentially exposed.<br><\/p>\n<\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">P<\/mark>opular online <a href=\"https:\/\/digitrendz.blog\/z\/topic\/code-formatting\/\" class=\"acp-topic-link\" data-topic-id=\"136718\" title=\"Explore: code formatting\" target=\"_blank\" rel=\"noopener noreferrer\">code formatting<\/a> platforms like <a href=\"https:\/\/digitrendz.blog\/z\/entity\/jsonformatter\/\" class=\"acp-entity-link\" data-entity-id=\"166303\" data-entity-category=\"product\" title=\"Learn more about JSONFormatter\" target=\"_blank\" rel=\"noopener noreferrer\">JSONFormatter<\/a> and <a href=\"https:\/\/digitrendz.blog\/z\/entity\/codebeautify\/\" class=\"acp-entity-link\" data-entity-id=\"166304\" data-entity-category=\"product\" title=\"Learn more about CodeBeautify\" target=\"_blank\" rel=\"noopener noreferrer\">CodeBeautify<\/a> have been found to inadvertently expose highly sensitive user data, including passwords, API keys, and confidential configuration files.<\/strong> Security analysts from <a href=\"https:\/\/digitrendz.blog\/z\/entity\/watchtowr\/\" class=\"acp-entity-link\" data-entity-id=\"30754\" data-entity-category=\"Organization\" title=\"Learn more about watchTowr\" target=\"_blank\" rel=\"noopener noreferrer\">watchTowr<\/a> uncovered that these widely used web services, which help developers tidy up and validate code, are leaking private information through publicly accessible links.<\/p>\n\n<p class=\"wp-block-paragraph\">These free tools allow users to format messy code, check its validity, or convert it into different structures. A save function lets individuals store their formatted output and share it with colleagues. According to the site\u2019s own FAQ, any code saved without a user account automatically becomes publicly viewable.<\/p>\n\n<p class=\"wp-block-paragraph\">Both websites feature a <strong>Recent Links section where anyone can browse through publicly saved outputs<\/strong>. Alarmingly, the researchers discovered that even links intended to remain private could be accessed because the websites use a predictable pattern for generating URLs. This vulnerability enabled watchTowr to systematically locate and collect over 80,000 saved JSON entries.<\/p>\n\n<p class=\"wp-block-paragraph\">Within this massive data haul, investigators identified a disturbing array of exposed secrets. The information included <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/active-directory\/\" class=\"acp-entity-link\" data-entity-id=\"20887\" data-entity-category=\"Technology\" title=\"Learn more about Active Directory\" target=\"_blank\" rel=\"noopener noreferrer\">Active Directory<\/a> login details, <a href=\"https:\/\/digitrendz.blog\/z\/entity\/github\/\" class=\"acp-entity-link\" data-entity-id=\"198\" data-entity-category=\"Organization\" title=\"Learn more about GitHub\" target=\"_blank\" rel=\"noopener noreferrer\">GitHub<\/a> access tokens, cloud service environment keys, and private cryptographic keys<\/strong>. Also found were credentials for CI\/CD pipelines, various API keys, internal configuration files, recorded SSH sessions, and personally identifiable information.<\/p>\n\n<p class=\"wp-block-paragraph\">Perhaps most concerning was the origin of these leaks. The compromised data belonged to organizations operating in <strong>highly regulated and critical industries<\/strong>, such as government agencies, financial institutions, healthcare providers, telecommunications firms, retail corporations, aerospace companies, educational bodies, and even cybersecurity firms.<\/p>\n\n<p class=\"wp-block-paragraph\">To gauge whether <a href=\"https:\/\/digitrendz.blog\/z\/topic\/malicious-actors\/\" class=\"acp-topic-link\" data-topic-id=\"114628\" title=\"Explore: malicious actors\" target=\"_blank\" rel=\"noopener noreferrer\">malicious actors<\/a> were already exploiting this security flaw, the team set up a trap. They inserted several <a href=\"https:\/\/digitrendz.blog\/z\/topic\/canary-tokens\/\" class=\"acp-topic-link\" data-topic-id=\"136720\" title=\"Explore: canary tokens\" target=\"_blank\" rel=\"noopener noreferrer\">canary tokens<\/a>, fake credentials designed to alert when accessed, into both JSONFormatter and CodeBeautify. The results were swift and unsettling. Within just 48 hours of saving the data, an unknown party attempted to use one of the decoy <a href=\"https:\/\/digitrendz.blog\/z\/entity\/aws\/\" class=\"acp-entity-link\" data-entity-id=\"648\" data-entity-category=\"Technology\" title=\"Learn more about AWS\" target=\"_blank\" rel=\"noopener noreferrer\">AWS<\/a> keys.<\/p>\n\n<p class=\"wp-block-paragraph\">This confirmed that threat actors are actively scraping these sites for valid credentials and testing them for unauthorized access. The researchers decided to disclose their findings publicly after their attempts to privately alert most of the affected organizations went largely unacknowledged.<\/p>\n\n<p class=\"wp-block-paragraph\">Although JSONFormatter has since made its Recent Links section inaccessible and temporarily disabled its save feature to prevent inappropriate content, CodeBeautify\u2019s public listing remains active. Security professionals, including researcher <a href=\"https:\/\/digitrendz.blog\/z\/entity\/kevin-beaumont\/\" class=\"acp-entity-link\" data-entity-id=\"21427\" data-entity-category=\"Person\" title=\"Learn more about Kevin Beaumont\" target=\"_blank\" rel=\"noopener noreferrer\">Kevin Beaumont<\/a>, warn that this is likely a widespread issue affecting numerous other online code formatting and beautification services.<\/p>\n\n<p class=\"wp-block-paragraph\">The underlying problem highlights a significant operational risk. <strong>Convenient web-based tools can pose serious security threats if they store or expose sensitive input data<\/strong>. Security experts stress that organizations, especially those in <a href=\"https:\/\/digitrendz.blog\/z\/topic\/critical-sectors\/\" class=\"acp-topic-link\" data-topic-id=\"74790\" title=\"Explore: critical sectors\" target=\"_blank\" rel=\"noopener noreferrer\">critical sectors<\/a>, should avoid pasting any confidential credentials or secrets into random third-party websites, no matter how useful they may seem.<\/p>\n\n<p class=\"wp-block-paragraph\"><em>(Source: <a href=\"https:\/\/www.helpnetsecurity.com\/2025\/11\/25\/code-formatting-sites-exposing-secrets\/\" target=\"_blank\" rel=\"noreferrer noopener\">HelpNet Security<\/a>)<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Popular online code formatting platforms like JSONFormatter and CodeBeautify are leaking sensitive user data, including passwords and API keys, through publicly accessible links due to predictable URL patterns. Security researchers found over 80,000 exposed entries containing critical information&#8230;<\/p>\n","protected":false},"author":1,"featured_media":89271,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[3253,3297,3327,3254],"tags":[127498,127499,127497,127500],"entities":[14147,2625,127185,1356,127186,127184,14673,127501,22086],"class_list":["post-89272","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","category-cybersecurity","category-newswire","category-technology","tag-api-key-compromise","tag-code-formatting-security","tag-data-leak-exposure","tag-jsonformatter-vulnerability","entity-active-directory","entity-aws","entity-codebeautify","entity-github","entity-json-formatter","entity-jsonformatter","entity-kevin-beaumont","entity-watchtower","entity-watchtowr"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/89272","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=89272"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/89272\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/89271"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=89272"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=89272"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=89272"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=89272"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}