Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Malicious JetBrains plugins steal AI API keys from developers

At least 15 malicious plugins on the JetBrains Marketplace, posing as AI coding assistants and development tools, exfiltrate AI provider API keys via HTTP to a hardcoded server when a user applies a key. These plugins, first published in October 2025 and active as recently as June 2026, have been installed tens of thousands of times. IT security professionals should audit and remove any suspicious or unofficial plugins from developer IDEs, particularly those offering AI coding assistance.
Read Full Article →

Supply chain Malicious JetBrains plugins steal AI API keys from developers June 17, 2026 Share By SC Staff As reported by Bleeping Computer, at least 15 malicious plugins discovered on the JetBrains Marketplace were designed to steal AI API keys from developers. These plugins, disguised as AI coding assistants and other development tools, were installed nearly 70,000 times. A coordinated malware campaign on the JetBrains Marketplace has been uncovered by Aikido Security, with at least 15 plugins published under seven vendor accounts exhibiting the same malicious behavior. These plugins, which function as AI coding assistants, code-review tools, and Git utilities, secretly exfiltrate AI provider API keys stored in their settings. The theft occurs when a user applies an API key, sending it over HTTP to a hardcoded server. Researchers from Aikido Security noted that the plugins were first published in October 2025 and continued to be released as recently as June 10, 2026. The plugins also feature a paid tier where harvested API keys from free users may be provided to paying customers. While download counts can be manipulated, two of the most downloaded plugins, DeepSeek AI Assist and CodeGPT AI Assistant, have been installed tens of thousands of times. This marks a less common type of threat on the JetBrains Marketplace compared to repositories like npm or PyPI. Source: Bleeping Computer SC Staff Related Critical Infrastructure Security AUR suspends new registrations as 1,500-plus malicious packages flood repository Laura French June 17, 2026 Malicious build scripts deploy a Rust-based infostealer and eBPF rootkit. Supply chain NPM v12 to block supply-chain attacks with new security measures SC Staff June 10, 2026 The upcoming npm v12 will introduce stricter security protocols for the "npm install" command, a critical step in downloading and installing project dependencies. Supply chain Mini Shai-Hulud ‘Hades’ variant affects 23 PyPI package versions Laura French June 10, 2026 The JavaScript stealer payload includes an anti-analysis LLM prompt injection. Related Events Cybercast From code to cloud: Stopping attacks in the software supply chain On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article