news.mlab.sh
Back to the feed
threat-intel

Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

High
Image: The Hacker News
Summary

A coordinated malware campaign targeting JetBrains Marketplace plugins has emerged, with 15 malicious plugins designed to steal AI API keys from users. These plugins, posing as AI coding assistants, exfiltrate keys to a remote server, potentially enabling illicit monetization schemes. Simultaneously, two Google Chrome extensions, dubbed PromptSnatcher, have been discovered capturing conversations with AI chatbots like ChatGPT and Gemini. This highlights a growing trend of threat actors targeting developer environments and AI services through open-source tools and telemetry collection.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.