Fifteen JetBrains Marketplace Plugins Found Stealing API Keys
ID: bbf382d7-ffa1-5351-8036-04eac325bfbf
STIX ID: report--bbf382d7-ffa1-5351-8036-04eac325bfbf
Feed Name: Infosecurity Magazine (News)
Aikido Security discovered at least 15 malicious JetBrains IDE plugins (dating from Oct 2025 to June 2026) installed ~70,000 times that pose as AI coding assistants; when users paste AI-provider API keys into plugin settings the key is immediately saved locally and exfiltrated to an attacker-controlled server, likely for resale or use to pay for model compute. The plugins function normally otherwise, include a paid tier that may distribute stolen keys, and Aikido published related IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
