Malicious JetBrains Plugins Exfiltrate AI API Keys from Developers

Malicious JetBrains Plugins Exfiltrate AI API Keys from Developers

First seen 16 Jun 2026, 22:41 UTC Aikido.DevBleepingcomputerInfosecurity-MagazineThehackernewsCybersecuritynews+1 90% similarity 71.0

Article Content

Browse articles
ThreatCluster

A coordinated malware campaign has been uncovered involving at least 15 malicious plugins on the JetBrains Marketplace, designed to steal AI API keys from developers. These plugins, masquerading as AI coding assistants, have been installed nearly 70,000 times since their first appearance in October 2025. Users unknowingly exfiltrate their API keys when they click 'Apply' after entering them into the plugin settings, which then sends the keys to a hardcoded server. The plugins also feature a paid tier, where users receive API keys in return for payment, potentially sourced from stolen credentials. The campaign continues to evolve, with new plugins being released as recently as June 10, 2026. The plugins have been confirmed to contain credential theft code, and the JetBrains Marketplace has yet to respond to inquiries about their removal.

Key Points: • At least 15 malicious JetBrains plugins have been identified, installed nearly 70,000 times. • The plugins exfiltrate AI API keys upon user input, sending them to a hardcoded server. • A paid tier allows users to receive API keys, likely sourced from stolen credentials.

ThreatCluster AI How this analysis works

Timeline

2025-10-01
First malicious plugins published
The initial versions of the malicious plugins appeared on the JetBrains Marketplace, beginning a coordinated campaign.
Aikido.Dev
2026-06-10
New plugins released
New versions of the malicious plugins were published on the JetBrains Marketplace, continuing the campaign.
Bleepingcomputer
2026-06-16
Aikido Security report published
Aikido Security published a detailed report on the malicious plugins, revealing their functionality and impact.
Aikido.Dev
2026-06-16
BleepingComputer confirms theft code
BleepingComputer independently analyzed the DeepSeek AI Assist plugin and confirmed the presence of credential theft code.
Bleepingcomputer
2026-06-17
Infosecurity Magazine coverage
Infosecurity Magazine reported on the coordinated campaign, summarizing the findings of Aikido Security.
Infosecurity-Magazine

Community

Browse all →