Toggle light / dark theme

Malicious JetBrains Marketplace plugins steal AI API keys from developers

At least 15 malicious plugins found on the JetBrains Marketplace were designed to steal AI API keys from developers.

The campaign, discovered by Aikido Security, includes plugins that act as AI coding assistants, code-review tools, and Git utilities powered by popular AI services such as OpenAI, DeepSeek, and SiliconFlow.

“We detected a coordinated malware campaign on the JetBrains Marketplace,” warns Aikido.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */