Executive Summary
In early 2024, researchers discovered that thousands of sensitive credentials, API keys, and authentication tokens belonging to global banks, government agencies, and technology companies were inadvertently exposed through public submissions to online code formatting tools such as JSONFormatter and CodeBeautify. These web-based beautifier platforms, commonly used by developers to format or debug code, were found to be storing users’ uploads—including confidential configuration files—in publicly accessible repositories without adequate warning or access control. As a result, threat actors could easily discover and exploit these exposed secrets to compromise critical infrastructure or initiate supply chain attacks.
This incident underscores the ongoing risks of third-party tool usage in secure development lifecycles. With data exposures driven by everyday tooling, organizations face mounting regulatory and operational scrutiny to audit developer practices, harden supply chain security, and implement broader controls for inadvertent credential leakage.
Why This Matters Now
As organizations increasingly rely on cloud-based developer tools, the careless handling or misconfiguration of such tools poses a growing risk of accidental data leaks and credential exposures. High-profile breaches like this highlight an urgent need for organizations to strengthen controls around sensitive data sharing and developer hygiene to prevent unintended security lapses.
Attack Path Analysis
Attackers discovered exposed credentials and secrets left in publicly accessible code beautifier tools, enabling initial access into sensitive organizational environments. Leveraging these credentials, threat actors were able to access privileged resources or escalate privileges if weak segmentation and controls existed. They moved laterally within cloud or hybrid networks, exploring additional workloads, services, and assets. Command and control channels allowed adversaries to maintain persistence, issue commands, and set up further infrastructure. Sensitive data, including additional secrets and configurations, were then exfiltrated using outbound network channels or API calls. The tangible impact ranged from unauthorized access and further compromise of cloud assets to exposure and misuse of confidential or regulated information.
Kill Chain Progression
Initial Compromise
Description
Attackers harvested plaintext credentials and API keys from public online code beautifier platforms and used them to gain initial access to affected organizations' cloud accounts and services.
MITRE ATT&CK® Techniques
Unsecured Credentials
Data from Information Repositories
Data from Cloud Storage Object
Automated Collection
Account Discovery
Exfiltration Over C2 Channel
Account Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Storage of Sensitive Authentication Data
Control ID: 3.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model (ZTMM) 2.0 – Protect Secrets and Credentials
Control ID: Identity Pillar, Authentication Strength
NIS2 Directive – Technical and Operational Measures
Control ID: Article 21(2)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Code beautifier data exposure threatens financial credentials and authentication keys, creating severe regulatory compliance risks under PCI DSS requirements.
Government Administration
Publicly exposed government authentication keys and configuration data pose national security risks requiring immediate zero trust segmentation implementation.
Information Technology/IT
Exposed IT credentials in code formatting tools enable lateral movement attacks, compromising multi-cloud visibility and egress security controls.
Health Care / Life Sciences
Healthcare credentials exposure violates HIPAA requirements for encrypted traffic and threatens patient data through compromised authentication systems.
Sources
- Code beautifiers expose credentials from banks, govt, tech orgshttps://www.bleepingcomputer.com/news/security/code-beautifiers-expose-credentials-from-banks-govt-tech-orgs/Verified
- Code beautifiers expose credentials from banks, govt, tech orgshttps://www.bleepingcomputer.com/news/security/code-formatters-expose-thousands-of-secrets-from-banks-govt-tech-orgs/Verified
- 80,000 code snippets From banks, governments, and technology company leaked: Cloud passwords, payment keys, personal data exposedhttps://timesofindia.indiatimes.com/technology/tech-news/80000-code-snippets-from-banks-governments-and-technology-company-leaked-cloud-passwords-payment-keys-personal-data-exposed/articleshow/125588296.cmsVerified
- Code Beautifiers Are Exposing High Risk Access Credentials Onlinehttps://botcrawl.com/code-beautifiers-are-exposing-high-risk-access-credentials-online/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive CNSF controls such as zero trust segmentation, east-west traffic security, encrypted traffic enforcement, and outbound egress filtering would have restricted attacker movement, limited credential misuse, and detected suspicious data exfiltration or anomalies across the cloud network.
Control: Multicloud Visibility & Control
Mitigation: Centralized monitoring would rapidly detect anomalous access patterns stemming from unusual authentication activity.
Control: Zero Trust Segmentation
Mitigation: Strict identity- and role-based segmentation blocks unauthorized privilege elevation.
Control: East-West Traffic Security
Mitigation: Internal traffic inspection and workload isolation disrupt lateral spread attempts.
Control: Cloud Firewall (ACF)
Mitigation: Inline firewalling detects and blocks suspicious outbound C2 channels.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound data transfer is restricted to authorized destinations and patterns.
Early anomaly detection accelerates response and limits the scale of impact.
Impact at a Glance
Affected Business Functions
- IT Operations
- Security Management
- Compliance
- Customer Data Management
Estimated downtime: 7 days
Estimated loss: $5,000,000
Sensitive credentials, including cloud service passwords, API keys, and personally identifiable information (PII) from organizations in sectors such as banking, government, and technology, were inadvertently exposed through unprotected 'Recent Links' features on code beautification platforms. This exposure could lead to unauthorized access, data breaches, and compliance violations.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce strong egress controls and outbound filtering to prevent data exfiltration and C2 communication.
- • Implement zero trust segmentation and least privilege policies to contain credential misuse and lateral movement.
- • Utilize east-west traffic inspection and microsegmentation to detect and block unauthorized internal communications.
- • Continuously monitor and audit credential usage and sensitive asset access across multicloud environments.
- • Deploy real-time anomaly detection and automated incident response to rapidly contain breaches and reduce impact.



