Malicious JetBrains Plugins Compromise AI API Keys

A recent investigation reveals a series of harmful plugins on the JetBrains Marketplace designed to steal AI provider keys.

3 min readCybersecurity

Cybersecurity experts have identified a significant malware operation targeting the JetBrains Marketplace, where at least 15 harmful plugins have been discovered. These plugins masquerade as AI coding assistants, leveraging popular models like DeepSeek to provide functionalities such as chat support, commit message generation, code reviews, bug detection, and unit testing. However, their true purpose is to extract sensitive API keys from users, posing a serious threat to developers relying on AI tools. Users are urged to exercise caution when installing plugins and to verify their authenticity to protect their valuable data and resources.

Cybersecurity