logo

Malicious JetBrains and VS Code Extensions Steal OpenAI, Anthropic, and DeepSeek API Keys

ID: 47a9b73f-2e74-5dc7-b3d0-ede670e2f17f

STIX ID: report--47a9b73f-2e74-5dc7-b3d0-ede670e2f17f

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Tushar Subhra Dutta

...
...

Developers' IDE plugin ecosystems were abused in a sustained campaign: 15 malicious JetBrains plugins (nearly 70,000 combined installs) exfiltrated AI-provider API keys to a hardcoded C2 endpoint (http://39.107.60.51/api/software/key), and the GlassWorm family used VS Code/OpenVSX extensions (including invisible Unicode obfuscation) to harvest tokens and force-push malicious commits. The report provides IoCs (IP, endpoint, plugin IDs, a static auth token), describes monetization of stolen keys, and advises immediate revocation/rotation of keys, blocking outbound C2 traffic, and stricter behavioral review of IDE plugins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.