Skip to main content

Coding assistance websites exposed credentials for banks, government, and more

Two websites intended to help software developers format and structure their code have exposed thousands of login credentials, authentication keys, and other highly sensitive information.

Cybersecurity researchers found that this sensitive data belonged to organizations in many high-risk sectors like government, banking, and healthcare …

JSONFormatter and CodeBeautify are two online tools that allow software developers to paste in their code and have it turned into a more readable format. However, when they save their results to reference later, whatever they include in their links is left completely exposed to anyone.

The issue is that in many cases the links included embedded credentials, authentication keys, and other highly sensitive information that could enable hackers to gain access to those systems.

Bleeping Computer reports that cybersecurity company watchTowr found over five years’ worth of JSONformatter data and a year of CodeBeautify data containing a wide array of sensitive information.

  • Active Directory credentials
  • Database and cloud credentials
  • Private keys
  • Code repository tokens
  • CI/CD secrets
  • Payment gateway keys
  • API tokens
  • SSH session recordings
  • Large amounts of personally identifiable information (PII), including know-your-customer (KYC) data
  • An AWS credential set used by an international stock exchange’s Splunk SOAR system
  • Credentials for a bank exposed by an MSSP onboarding email

Ironically, this included sensitive information from an easily-identifiable cybersecurity company.

At the time of writing, the links are still freely accessible on both platforms.

Highlighted accessories

Photo by James Harrison on Unsplash

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Ben Lovejoy Ben Lovejoy

Ben Lovejoy is a British technology writer and EU Editor for 9to5Mac. He’s known for his op-eds and diary pieces, exploring his experience of Apple products over time, for a more rounded review. He also writes fiction, with two technothriller novels, a couple of SF shorts and a rom-com!


Ben Lovejoy's favorite gear