Multiple JetBrains IDE plugins caught stealing AI keys
ID: 7969b308-fc5b-56a6-bbf3-941c51d10c6f
STIX ID: report--7969b308-fc5b-56a6-bbf3-941c51d10c6f
Feed Name: Aikido Security's Blog
Threat Score
A coordinated supply-chain malware campaign on the JetBrains Marketplace distributed at least 15 IDE plugins (published under seven vendor accounts) that silently exfiltrate users' AI provider API keys to a hardcoded C2 server (39.107.60.51). The report includes code snippets demonstrating immediate key theft on settings save, a list of affected plugins and vendor accounts, evidence of key resale to paying users, and recommendations for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
