Virtual Event: Threat Detection & Incident Response Summit - Watch Now
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Thousands of Secrets Leaked on Code Formatting Platforms

JSONFormatter and CodeBeautify users exposed credentials, authentication keys, configuration information, private keys, and other secrets.

Developer security vulnerability

Users of code formatting platforms are exposing thousands of secrets and other types of sensitive information, attack surface management provider WatchTowr warns.

GitHub found roughly 39 million inadvertently leaked secrets across the platform last year, and previous research has revealed that secrets exposed on Git-based Source Code Management systems (SCMs) remain permanently leaked.

But users’ blunders extend beyond unknowingly hardcoding secrets in code published to public repositories. Every online tool used without proper code sanitization may lead to a leak. And threat actors are hunting them like hawks.

This is the conclusion WatchTowr reached after analyzing roughly 80,000 saved JSON files collected from JSONFormatter and CodeBeautify, platforms that users rely on to ‘beautify’ their code.

In its dataset, the outfit found thousands of sensitive secrets, including credentials, keys, tokens, configuration files, SSH session recordings, sensitive API requests and responses, personally identifiable information (PII), and other types of sensitive information.

In one case, someone apparently exported all credentials for their AWS Secrets Manager to a code formatting solution.

Advertisement. Scroll to continue reading.

Cybersecurity and critical infrastructure entities affected

The leaked secrets belong to organizations across multiple verticals, including technology and cybersecurity, critical national infrastructure, government, finance, healthcare, aerospace, insurance, banking, education, telecoms, travel, and more.

The problem is not that people use these platforms to format and beautify the code in their enterprise or personal projects.

The issue is that some of them save the projects to create links to the code, which can be shared, and that these platforms allow visitors to scroll through recently saved content and associated URLs.

WatchTowr used the ‘Recent Links’ pages of both JSONFormatter and CodeBeautify to fetch over five gigabytes of JSON data, representing years of historical content.

After analyzing the data, it attempted to contact high-profile organizations impacted by the leaks, and worked with CERT teams to reach more entities.

By placing fake credentials in these JSON formatting platforms, the cybersecurity firm discovered that others were also scraping the databases and that exposed secrets are used within days after being leaked.

“We don’t need more AI-driven agentic agent platforms; we need fewer critical organizations pasting credentials into random websites,” WatchTowr notes.

Related: Many Forbes AI 50 Companies Leak Secrets on GitHub

Related: Files Deleted From GitHub Repos Leak Valuable Secrets

Related: PyPI Packages Found to Expose Thousands of Secrets

Related: Thousands of Popular Websites Leaking Secrets

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.