Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› JSONFormatter and CodeBeautify Leak 2025: How Saved Code…
Breach analysis Incident: 25 Nov 2025

JSONFormatter and CodeBeautify Leak 2025: How Saved Code Formatter Links Exposed 80,000+ Pastes of Secrets

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 27 September 2026 12 min read
On this page

On 25 November 2025, watchTowr Labs published research showing that two popular online code formatting sites, JSONFormatter and CodeBeautify, had been quietly publishing the secrets that developers and administrators pasted into them. Both sites let users save formatted content and share it as a link, and both listed those saved links on a public "Recent Links" page. By walking those pages, watchTowr downloaded more than 80,000 saved submissions, over 5GB of data, covering about five years of JSONFormatter saves and one year of CodeBeautify saves. The pastes held Active Directory passwords, cloud keys, GitHub tokens, database credentials, private keys and CI/CD secrets from organisations in government, banking, critical national infrastructure, cybersecurity and other sectors. A canary test showed someone else was already scraping the same data and trying the keys. Nothing was hacked in the usual sense: the exposure came from people handing machine credentials to a free website with a public share feature.

Key takeaways

  • watchTowr Labs researcher Jake Knott published the findings on 25 November 2025, after months of outreach to affected organisations with the help of national cyber agencies including NCSC UK and CISA.
  • The entry point was a by-design "Recent Links" page on both sites that let anyone browse saved content, combined with predictable link formats and a retrieval endpoint that returned the saved data.
  • The exposed material was dominated by non-human identity secrets: AWS keys, a full AWS Secrets Manager export, GitHub tokens, Docker Hub, JFrog and Grafana credentials, database passwords, Jenkins secrets, keytabs and private key passwords, alongside Active Directory credentials and customer personal data.
  • Fake AWS keys planted by watchTowr, set to expire after 24 hours, were tested by an unknown party 48 hours after upload, showing that attackers were already harvesting these sites.
  • Lesson: any secret pasted into an external tool must be treated as leaked. Organisations need to control where credentials go, detect them outside their own systems and rotate them quickly.

At a glance

PlatformsJSONFormatter (jsonformatter.org) and CodeBeautify (codebeautify.org), free online code formatting and validation tools
ResearcherswatchTowr Labs (Jake Knott)
Disclosed25 November 2025; organisations contacted months earlier
AffectedOrganisations whose staff saved sensitive pastes, in sectors including government, critical national infrastructure, finance, banking, insurance, technology, cybersecurity, aerospace, telecoms, healthcare, education, retail and travel
Entry pointPublic "Recent Links" pages listing saved content, predictable link formats and a data retrieval endpoint
Identities exposedAWS and other cloud keys, AWS Secrets Manager contents, GitHub tokens, CI/CD and Jenkins secrets, Docker Hub, JFrog, Grafana and RDS credentials, Kerberos keytabs, private key passwords, Active Directory and database credentials
ImpactMore than 80,000 saved submissions and over 5GB of data collected by watchTowr; canary keys tested by a third party within 48 hours of upload
CategoryNHI (secrets exposure through third-party developer tools)

What happened

JSONFormatter and CodeBeautify are free web tools that tidy up and validate JSON, XML, YAML and other code. Developers use them every day to make a messy configuration file or API response readable. Both sites also offer a save feature that stores the content and gives it a shareable link. watchTowr found that these saved items were not private. Both sites had a "Recent Links" page, which watchTowr describes as "a by-design feature on both JSONformatter and CodeBeautify that allows a random user (you, me, your parrot) to browse all saved content and their associated links, along with the associated title, description, and date."

The saved links followed simple formats, such as https://jsonformatter.org/{id} and https://codebeautify.org/{formatter-type}/{id}, and the sites fetched the content through a POST /service/getDataFromID request. With those pieces, watchTowr could list and download saved submissions at scale. The team says it captured "80,000+ downloaded submissions (and that's just where we decided to stop)" and more than 5GB of enriched, annotated JSON. From the 35,000 pages of historical links on JSONFormatter, each holding ten results, watchTowr inferred "circa 350,000 saved uploads since inception" on that site alone.

The researchers then searched the data for secrets. They report Active Directory credentials, code repository authentication keys, database credentials, cloud environment keys, private keys, payment gateway credentials, SSH session recordings, several kinds of personal data and "an entire export of every single credential from someone's AWS Secrets Manager".

watchTowr's write-up walks through several examples, without naming the organisations. A university student with access to MITRE CoDev projects saved a Jenkins configuration containing encrypted secrets, service account credentials and private keys. A government entity pasted more than 1,000 lines of PowerShell deployment scripts with internal endpoints, administrative usernames and hardening settings. A datalake-as-a-service vendor exposed Docker Hub, JFrog, Grafana and Amazon RDS credentials. A cybersecurity company leaked SSL certificate private key passwords and Service Principal Name keytab credentials. A major consulting firm exposed multiple GitHub tokens and hardcoded credentials. A managed security service provider employee uploaded "Active Directory credentials for a BANK" together with onboarding details, and a bank exposed customer know-your-customer records including links to recorded video interviews. BleepingComputer also reported an AWS credential set used by an international stock exchange's Splunk SOAR system.

To test whether anyone else was reading these sites, watchTowr generated tracked fake AWS keys with the Canarytokens service and saved them on the formatting platforms with a 24-hour expiry. According to watchTowr, "they were tested 48 hours after our initial upload and save", which is 24 hours after the link had expired and the content was supposed to be gone. Its conclusion: "someone else is already scraping these sources for credentials, and actively testing them."

Before publishing, watchTowr says it contacted "a significant number of high-profile organizations", with help from NCSC UK, NCSA Greece, the Canadian Centre for Cyber Security, CISA, CERT PL, CERT EU and CERT FR. Only a handful responded quickly, and "The majority didn't bother."

Timeline

DateEvent
About five years before publicationOldest JSONFormatter saves in watchTowr's dataset; CodeBeautify data covers about one year (watchTowr).
Months before 25 November 2025watchTowr contacts affected organisations with support from national agencies including NCSC UK, CISA and CERT EU.
During the research (date not published)watchTowr saves canary AWS keys with a 24-hour expiry; they are tested 48 hours after upload.
25 November 2025watchTowr Labs publishes its research; BleepingComputer, The Hacker News and Help Net Security report it the same day.
25 November 2025The Hacker News reports both sites have temporarily disabled saving; Help Net Security reports JSONFormatter's Recent Links page is inaccessible while CodeBeautify's is still reachable.
26 November 2025SecurityWeek covers the findings.
5 December 2025watchTowr's post shows an update date of 5 December 2025.

How it happened: the identity attack path

  1. Secrets leave the organisation in a paste. Staff pasted configuration files, scripts, API responses and credential exports into a free online formatter to make them readable, carrying live machine credentials with them.
  2. Save and share turns a tool into a publisher. Saving the output to get a shareable link stored the content on the site's servers, outside any control the organisation had.
  3. Public listing makes the data discoverable. The Recent Links pages listed saved items with their titles, descriptions and dates, so anyone could browse them without guessing links.
  4. Predictable retrieval enables bulk collection. Simple link formats and a retrieval endpoint let watchTowr, and anyone else, download tens of thousands of submissions automatically.
  5. Secrets are extracted and tested. The canary experiment showed an unknown party collecting the data and trying AWS keys within 48 hours of upload, even after the saved link had expired.
  6. Long-lived credentials extend the window. Much of the exposed material, such as Active Directory passwords, keytabs, GitHub tokens and cloud keys, stays valid until someone rotates it, so a paste from years earlier can still grant access.

Impact

  • Scale: watchTowr collected more than 80,000 saved submissions and over 5GB of data, and estimated around 350,000 saved uploads on JSONFormatter alone. SecurityWeek described the set as "roughly 80,000 saved JSON files".
  • Reach: the affected organisations span government, critical national infrastructure, banking, finance, insurance, technology, cybersecurity, aerospace, telecoms, healthcare, education, retail and travel, according to watchTowr.
  • Credentials: cloud keys, repository tokens, CI/CD secrets, database and directory passwords and private key material, including a complete AWS Secrets Manager export.
  • Active exploitation risk: watchTowr's canary keys were tested by an unknown party, so the exposed secrets were not only theoretically available but being harvested.
  • Personal data: watchTowr found KYC records for bank customers and employee onboarding details, including security questions and answers.
  • Platform changes: The Hacker News reported that both sites had "temporarily disabled the save functionality", citing "enhanced NSFW (Not Safe For Work) content prevention measures".

What this means for NHI governance

This is a secrets sprawl story rather than a breach of either website. The sites worked as designed. The failure was that the credentials of cloud accounts, build servers, repositories and databases were copied into a third-party service that nobody in the owning organisation had approved, recorded or could see. Once the paste was saved, those non-human identities were effectively public, and there was no alert, no owner notified and no expiry on the credentials themselves.

Three points stand out. First, the everyday developer workflow is a leak path. Formatters, diff tools, paste sites and AI chat tools all receive raw configuration files, and a configuration file is often where machine credentials live. Second, deleting or expiring the paste is not remediation. watchTowr's canary keys were tested after the link had expired, which means anything pasted must be assumed copied. The only reliable fix is to revoke and rotate the credential. Third, the long tail matters. Years of saved content remained browsable, and static secrets such as keytabs, directory passwords and access keys often outlive the projects they were created for.

The pattern matches other exposure studies we have covered, including 17,000 secrets in public GitLab repositories and secrets in 10,000 Docker Hub images. In each case the secret escaped through an ordinary publishing feature, not an exploit.

Recommendations

  • Treat any pasted secret as compromised. If a credential has been pasted into an external formatter, paste site or chat tool, revoke and rotate it rather than deleting the paste. Challenges of Rotating NHIs explains why rotation needs planning before an incident.
  • Offer approved local tools. Provide formatters in IDEs or offline utilities, and block or warn on public formatting and paste sites through web filtering where practical.
  • Keep secrets out of configuration files. Store credentials in a secrets manager and reference them at runtime, so files that get shared do not contain live values. The Secrets Management Guide covers the patterns.
  • Prefer short-lived credentials. Replace static access keys, tokens and service account passwords with short-lived, federated credentials, so a leaked value expires quickly. See static vs dynamic secrets.
  • Monitor outside your own estate. Scan public sources for your organisation's secrets and domains, and consider canary credentials of your own to detect when data has escaped.
  • Know which NHIs exist and who owns them. An inventory with named owners makes it possible to act quickly when a key turns up somewhere it should not be, as set out in the secret sprawl challenge.
  • Train staff on the risk. Make clear that "save" or "share" on a free web tool can mean public, and that screenshots of credentials in tickets and chats carry the same risk.

Frequently asked questions

What happened with JSONFormatter and CodeBeautify?

watchTowr Labs found that content saved on the two code formatting sites could be browsed through public "Recent Links" pages. In research published on 25 November 2025, it said it had downloaded more than 80,000 saved submissions containing passwords, cloud keys, tokens and other secrets from organisations in many sectors.

Were the leaked credentials actually used by attackers?

watchTowr planted fake AWS keys on the platforms with a 24-hour expiry. An unknown party tested them 48 hours after upload, which watchTowr says shows someone was already scraping the sites for credentials and trying them. It did not publish evidence of specific organisations being breached through the exposed data.

What should I do if I pasted secrets into an online formatter?

Assume the secret is exposed. Revoke and rotate the credential, review logs for use of it since the paste was made, and move the value into a secrets manager so it no longer sits in configuration files that people copy around.

17,000 secrets in public GitLab repositories · Docker Hub leak of 10,000 images · iOS apps leaking secrets · The secret sprawl challenge · Secrets Management Guide · NHI breaches

How NHI Mgmt Group can help

The JSONFormatter and CodeBeautify findings show that cloud keys, tokens and service account passwords leak through everyday tools long before anyone notices. Our NHI Foundation Level Training Course helps teams inventory, own and rotate these non-human identities so a leaked secret is short-lived and quickly contained.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 27 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org