Find notable cyber news and cases, enriched with sources, timelines, and signals.

JetBrains Marketplace malicious plugin API-key theft campaign

Campaign
First reported
Last updated
Happening score
H score 15
3 unique sources, 3 articles

Summary

Hide ▲

A coordinated malware campaign on the JetBrains Marketplace is stealing developers' AI provider API keys through malicious plugins that pose as AI coding assistants, code-review tools, and Git utilities. The operation spans at least 15 plugins under seven vendor accounts and sends stolen keys to 39.107.60[.]51 over HTTP. The campaign has been active since October 2025 and continued with new uploads as recently as June 10, 2026. One analyzed plugin remained available for download, keeping the theft path active.

Related Happenings

JetBrains Marketplace malicious plugins exfiltrating AI provider keys

Malware Activity
H score12 First: 17.06.2026 12:38 Last: 17.06.2026 12:38 Sources 1

How related: Cybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys.

About this happening: A JetBrains Marketplace malware operation has pushed 15 malicious plugins that pose as AI coding assistants and steal AI provider API keys from developers. The plugins...

Developers' AI provider API keys exfiltrated via malicious JetBrains plugins

Data Leak
H score12 First: 17.06.2026 12:10 Last: 17.06.2026 12:10 Sources 1

How related: However, the AI provider API key you enter gets exfiltrated to a server controlled by the attacker.

About this happening: Developers' AI provider API keys were exfiltrated through malicious JetBrains Marketplace plugins, exposing credentials from a broad user base and risking unauthorized...

Contagious Interview UNK_DeadDrop GitHub phishing campaign

Campaign
H score37 First: 15.06.2026 22:32 Last: 15.06.2026 22:32 Sources 1

About this happening: The Contagious Interview cluster is running the UNK_DeadDrop phishing campaign to lure developers with recruitment and code review themes, reaching nearly 100 or...

GlassWorm malware abuses compromised OpenVSX extensions to steal credentials from macOS systems

Malware Activity
H score28 First: 03.02.2026 00:04 Last: 03.02.2026 00:04 Sources 1

About this happening: GlassWorm is a malware campaign that now also fuels ForceMemo, a supply-chain attack that steals GitHub tokens and force-pushes malicious code into Python reposi...

Developers' source code exposed through malicious VS Code extensions

Data Leak
H score29 First: 26.01.2026 17:43 Last: 26.01.2026 17:43 Sources 1

About this happening: Malicious VS Code extensions have been found exfiltrating developers' source code and workspace changes to China-based servers, exposing sensitive code across 1.5 mi...

Timeline

  1. 17.06.2026 00:54 4 articles · 29d ago

    Malicious JetBrains Marketplace plugins steal AI API keys

    Initial Disclosure

    Aikido Security detected a coordinated malware campaign on the JetBrains Marketplace in which at least 15 IDE plugins under seven vendor accounts secretly exfiltrated developers' AI provider API keys from plugin settings to a hardcoded server at 39.107.60[.]51 over HTTP. The plugins posed as AI coding assistants, code-review tools, and Git utilities powered by OpenAI, DeepSeek, and SiliconFlow, and BleepingComputer independently confirmed that the latest DeepSeek AI Assist plugin still contained the credential theft code while it remained available for download.

    Show sources