Bleepingcomputer Malicious JetBrains Plugins Exfiltrate AI API Keys from Developers
Article Content
- •At least 15 malicious JetBrains plugins have been identified, installed nearly 70,000 times.
- •The plugins exfiltrate AI API keys upon user input, sending them to a hardcoded server.
- •A paid tier allows users to receive API keys, likely sourced from stolen credentials.
A coordinated malware campaign has been uncovered involving at least 15 malicious plugins on the JetBrains Marketplace, designed to steal AI API keys from developers. These plugins, masquerading as AI coding assistants, have been installed nearly 70,000 times since their first appearance in October 2025. Users unknowingly exfiltrate their API keys when they click 'Apply' after entering them into the plugin settings, which then sends the keys to a hardcoded server. The plugins also feature a paid tier, where users receive API keys in return for payment, potentially sourced from stolen credentials. The campaign continues to evolve, with new plugins being released as recently as June 10, 2026. The plugins have been confirmed to contain credential theft code, and the JetBrains Marketplace has yet to respond to inquiries about their removal.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track CodeGPT AI Assistant and OpenAI in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…