Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious JetBrains Marketplace plugins steal AI API keys from developers

0
Medium
Vulnerability
Published: Tue Jun 16 2026 (06/16/2026, 21:54:50 UTC)
Source: Bleeping Computer

Description

At least 15 malicious plugins on the JetBrains Marketplace were designed to steal AI API keys from developers. These plugins, masquerading as AI coding assistants and code-review tools, exfiltrate API keys entered by users to a hardcoded external server. The campaign began in October 2025 and continued through June 2026, with the plugins collectively installed nearly 70,000 times. The plugins also feature a paid tier that provides users with API keys sourced from stolen credentials. Despite the malicious behavior, the plugins function as advertised, complicating detection. As of the report date, some malicious plugins remain available on the JetBrains Marketplace. JetBrains had not responded to inquiries about the issue at the time of reporting.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/16/2026, 22:00:35 UTC

Technical Analysis

A coordinated malware campaign on the JetBrains Marketplace involves at least 15 IDE plugins published under seven vendor accounts that steal AI provider API keys from developers. When users enter their API keys into plugin settings and click "Apply," the keys are sent over HTTP to a hardcoded server (39.107.60.51). The plugins operate as legitimate AI tools but secretly exfiltrate credentials. The attackers appear to harvest free users' API keys and redistribute them to paid users via a donation-based tier. The campaign started in October 2025 and continued through June 2026, with nearly 70,000 installations. Analysis confirmed the presence of credential theft code in the DeepSeek AI Assist plugin, which remained available on the marketplace at the time of reporting. No vendor advisory or patch information is available, and JetBrains had not publicly addressed the issue.

Potential Impact

The malicious plugins compromise developer AI API keys, potentially allowing attackers to misuse these credentials for unauthorized AI service access. This can lead to unauthorized usage charges, loss of control over API keys, and potential abuse of AI services under the victim's account. The plugins' legitimate functionality may reduce suspicion, increasing the risk of prolonged credential theft. The redistribution of stolen keys to paid users also indicates a fraudulent monetization scheme. There is no evidence of broader system compromise beyond API key theft.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until official action is taken, users should avoid installing or using plugins from untrusted or unknown vendors on the JetBrains Marketplace. Developers should review and revoke any AI API keys that may have been entered into these plugins. Monitoring for unusual API usage and rotating API keys regularly is recommended. JetBrains users should await official communication and updates from JetBrains regarding removal or blocking of malicious plugins.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/malicious-jetbrains-marketplace-plugins-steal-ai-api-keys-from-developers/","fetched":true,"fetchedAt":"2026-06-16T22:00:27.430Z","wordCount":857}

Threat ID: 6a31c77b0b89be68883747f8

Added to database: 6/16/2026, 10:00:27 PM

Last enriched: 6/16/2026, 10:00:35 PM

Last updated: 6/17/2026, 5:08:36 AM

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses