At least 15 plugins listed in the JetBrains Marketplace were built to steal AI service API keys from developers who installed them. Aikido Security says the plugins, published under seven vendor accounts since October 2025 and still appearing as late as June 10, 2026, exfiltrated keys entered into plugin settings to a hardcoded server over HTTP, including credentials for OpenAI, DeepSeek, and SiliconFlow. The plugins reportedly posed as AI coding assistants, code-review tools, and Git utilities, with nearly 70,000 total downloads claimed across the set.
Why it matters: Developers and organizations using JetBrains IDEs may have had sensitive AI credentials stolen, creating risk of unauthorized model access, data exposure, and billing abuse. Affected users should remove the named plugins, rotate exposed API keys immediately, and review usage logs and downstream secrets access.
info@thehackernews.com (The Hacker News)
2026.06.17
97% relevant
This article appears to cover the same underlying campaign of malicious JetBrains Marketplace plugins stealing AI service credentials from developers, while adding related detail that Chrome extensions were also used to capture chatbot chats.
Lawrence Abrams
2026.06.16
100% relevant
This article appears to be the first concrete report establishing a coordinated malicious-plugin campaign in the JetBrains Marketplace focused on stealing AI API keys.
← Back to all stories