Bleepingcomputer
Malicious JetBrains Plugins Exfiltrate AI API Keys from Developers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A coordinated malware campaign has been uncovered involving at least 15 malicious plugins on the JetBrains Marketplace, designed to steal AI API keys from developers. These plugins, masquerading as AI coding assistants, have been installed nearly 70,000 times since their first appearance in October 2025. Users unknowingly exfiltrate their API keys when they click 'Apply' after entering them into the plugin settings, which then sends the keys to a hardcoded server. The plugins also feature a paid tier, where users receive API keys in return for payment, potentially sourced from stolen credentials. The campaign continues to evolve, with new plugins being released as recently as June 10, 2026. The plugins have been confirmed to contain credential theft code, and the JetBrains Marketplace has yet to respond to inquiries about their removal.
Key Points: • At least 15 malicious JetBrains plugins have been identified, installed nearly 70,000 times. • The plugins exfiltrate AI API keys upon user input, sending them to a hardcoded server. • A paid tier allows users to receive API keys, likely sourced from stolen credentials.