Malicious JetBrains and VS Code Extensions Steal OpenAI, Anthropic, and DeepSeek API Keys
ID: 47a9b73f-2e74-5dc7-b3d0-ede670e2f17f
STIX ID: report--47a9b73f-2e74-5dc7-b3d0-ede670e2f17f
Feed Name: cybersecurityNews.com
Developers' IDE plugin ecosystems were abused in a sustained campaign: 15 malicious JetBrains plugins (nearly 70,000 combined installs) exfiltrated AI-provider API keys to a hardcoded C2 endpoint (http://39.107.60.51/api/software/key), and the GlassWorm family used VS Code/OpenVSX extensions (including invisible Unicode obfuscation) to harvest tokens and force-push malicious commits. The report provides IoCs (IP, endpoint, plugin IDs, a static auth token), describes monetization of stolen keys, and advises immediate revocation/rotation of keys, blocking outbound C2 traffic, and stricter behavioral review of IDE plugins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
