


Perceptive Security
SOC/SIEM Consultancy

Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys
Published:
25 November 2025 at 16:49:00
Alert date:
5 December 2025 at 08:03:22
Source:
thehackernews.com

Cybersecurity research reveals that organizations in sensitive sectors including governments, telecoms, and critical infrastructure have been pasting passwords and credentials into online code formatting tools JSONformatter and CodeBeautify. WatchTowr Labs captured over 80,000 files from these sites, exposing thousands of sensitive credentials. The leaked data includes passwords, API keys, and other authentication materials from organizations across various critical sectors, creating significant security risks.
Technical details
Mitigation steps:
Affected products:
JSONformatter
CodeBeautify
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.