JetBrains Marketplace malicious plugin API-key theft campaign
Campaign
Summary
Hide ▲
Show ▼
A coordinated malware campaign on the JetBrains Marketplace is stealing developers' AI provider API keys through malicious plugins that pose as AI coding assistants, code-review tools, and Git utilities. The operation spans at least 15 plugins under seven vendor accounts and sends stolen keys to 39.107.60[.]51 over HTTP. The campaign has been active since October 2025 and continued with new uploads as recently as June 10, 2026. One analyzed plugin remained available for download, keeping the theft path active.
Related Happenings
JetBrains Marketplace malicious plugins exfiltrating AI provider keys
Malware Activity
H score12
First: 17.06.2026 12:38
Last: 17.06.2026 12:38
Sources 1
How related:
Cybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys.
About this happening:
A JetBrains Marketplace malware operation has pushed 15 malicious plugins that pose as AI coding assistants and steal AI provider API keys from developers. The plugins...
JetBrains Marketplace malicious plugins exfiltrating AI provider keys
Malware ActivityHow related: Cybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys.
About this happening: A JetBrains Marketplace malware operation has pushed 15 malicious plugins that pose as AI coding assistants and steal AI provider API keys from developers. The plugins...
Developers' AI provider API keys exfiltrated via malicious JetBrains plugins
Data Leak
H score12
First: 17.06.2026 12:10
Last: 17.06.2026 12:10
Sources 1
How related:
However, the AI provider API key you enter gets exfiltrated to a server controlled by the attacker.
About this happening:
Developers' AI provider API keys were exfiltrated through malicious JetBrains Marketplace plugins, exposing credentials from a broad user base and risking unauthorized...
Developers' AI provider API keys exfiltrated via malicious JetBrains plugins
Data LeakHow related: However, the AI provider API key you enter gets exfiltrated to a server controlled by the attacker.
About this happening: Developers' AI provider API keys were exfiltrated through malicious JetBrains Marketplace plugins, exposing credentials from a broad user base and risking unauthorized...
Contagious Interview UNK_DeadDrop GitHub phishing campaign
Campaign
H score37
First: 15.06.2026 22:32
Last: 15.06.2026 22:32
Sources 1
About this happening:
The Contagious Interview cluster is running the UNK_DeadDrop phishing campaign to lure developers with recruitment and code review themes, reaching nearly 100 or...
Contagious Interview UNK_DeadDrop GitHub phishing campaign
CampaignAbout this happening: The Contagious Interview cluster is running the UNK_DeadDrop phishing campaign to lure developers with recruitment and code review themes, reaching nearly 100 or...
GlassWorm malware abuses compromised OpenVSX extensions to steal credentials from macOS systems
Malware Activity
H score28
First: 03.02.2026 00:04
Last: 03.02.2026 00:04
Sources 1
About this happening:
GlassWorm is a malware campaign that now also fuels ForceMemo, a supply-chain attack that steals GitHub tokens and force-pushes malicious code into Python reposi...
GlassWorm malware abuses compromised OpenVSX extensions to steal credentials from macOS systems
Malware ActivityAbout this happening: GlassWorm is a malware campaign that now also fuels ForceMemo, a supply-chain attack that steals GitHub tokens and force-pushes malicious code into Python reposi...
Developers' source code exposed through malicious VS Code extensions
Data Leak
H score29
First: 26.01.2026 17:43
Last: 26.01.2026 17:43
Sources 1
About this happening:
Malicious VS Code extensions have been found exfiltrating developers' source code and workspace changes to China-based servers, exposing sensitive code across 1.5 mi...
Developers' source code exposed through malicious VS Code extensions
Data LeakAbout this happening: Malicious VS Code extensions have been found exfiltrating developers' source code and workspace changes to China-based servers, exposing sensitive code across 1.5 mi...
Timeline
-
17.06.2026 00:54 4 articles · 29d ago
Malicious JetBrains Marketplace plugins steal AI API keys
Initial DisclosureAikido Security detected a coordinated malware campaign on the JetBrains Marketplace in which at least 15 IDE plugins under seven vendor accounts secretly exfiltrated developers' AI provider API keys from plugin settings to a hardcoded server at 39.107.60[.]51 over HTTP. The plugins posed as AI coding assistants, code-review tools, and Git utilities powered by OpenAI, DeepSeek, and SiliconFlow, and BleepingComputer independently confirmed that the latest DeepSeek AI Assist plugin still contained the credential theft code while it remained available for download.
Show sources
- Malicious JetBrains Marketplace plugins steal AI API keys from developers — www.bleepingcomputer.com — 17.06.2026 00:54
- Malicious JetBrains Marketplace plugins steal AI API keys from developers — www.bleepingcomputer.com — 17.06.2026 00:54
- Fifteen JetBrains Marketplace Plugins Found Stealing API Keys — www.infosecurity-magazine.com — 17.06.2026 12:10
- Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats — thehackernews.com — 17.06.2026 12:38