Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Confidence Lacks in Threat Detection Across Non-Email Channels

June 19, 2026

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

June 19, 2026

Cybercrime Surges in APAC as Digitalization Takes Hold

June 19, 2026
Facebook X (Twitter) Instagram
Friday, June 19
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Fifteen JetBrains Marketplace Plugins Steal API Keys
News

Fifteen JetBrains Marketplace Plugins Steal API Keys

Team-CWDBy Team-CWDJune 18, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Security researchers have uncovered a coordinated campaign designed to steal developers’ AI-related API keys via malicious plugins.

Aikido Security found at least 15 integrated development environment (IDE) plugins on the JetBrains Marketplace which had slipped past security checks and have now been installed around 70,000 times.

They apparently date back to October 2025, with the most recent plugins released in June 2026.

“Every plugin poses as an AI coding assistant built on DeepSeek and other large language models, offering chat, commit messages, code review, bug finding, and unit tests,” said Aikido.

“They function exactly as advertised. However, the AI provider API key you enter gets exfiltrated to a server controlled by the attacker.”

Read more on IDE threats: Flaws in Popular Software Development App Extensions Allow Data Exfiltration

Aikido explained that all the malicious plugins it has found so far share a similar underlying codebase. They have names like “DeepSeek Git Commit” and “AI Coder Review.”

“To use any of them, you open the settings panel and paste in an API key for a provider such as OpenAI, SiliconFlow, or DeepSeek. The plugin needs that key to call the model on your behalf, so handing it over feels routine,” the report explained.

“The moment you click Apply, the settings handler stores your key and also forwards it to the attacker using the save() method. The call fires immediately on key entry, with no prompt, no consent screen, and no mention anywhere in the user interface.”

What’s the End Goal?

It’s not clear what the aim of the campaign is, although API keys connecting to paid AI services could be resold or used for compute.

Aikido suggested the first scenario may be applicable here, given that the plugins feature a paid tier. After the user pays a small fee via the donation wall built into the plugin, they apparently receive an API key from the server with which to make free calls to the relevant model.

Aikido hypothesized that these could be API keys exfiltrated from victims, turning the campaign into a service effectively reselling stolen API access

“The operator collects money on one side and free credentials on the other, while the genuine key owners pay the bill,” it added.

The report claimed that IDEs are an increasingly popular target for threat actors, given that they’re trusted, left open all day by developers, and provide access to a wealth of source code, cloud credentials, signing keys, and API keys.

Aikido shared the relevant IoCs in its blog post.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleLangflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE
Next Article Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
Team-CWD
  • Website

Related Posts

News

Confidence Lacks in Threat Detection Across Non-Email Channels

June 19, 2026
News

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

June 19, 2026
News

Cybercrime Surges in APAC as Digitalization Takes Hold

June 19, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

The WhatsApp screen-sharing scam you didn’t see coming

November 6, 2025

The hidden risks of browser extensions – and how to avoid them

September 13, 2025

Fixing trivial passwords is as easy as 123456

May 7, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.