threat-intel
Malicious JetBrains Marketplace plugins steal AI API keys from developers
High
Summary
A coordinated malware campaign involving 15 malicious plugins for the JetBrains Marketplace was discovered, designed to steal AI API keys from developers. These plugins, disguised as AI coding assistants and code review tools, secretly transmitted user-entered API keys to a remote server. The campaign, active since October 2025, has seen over 70,000 installations and highlights a concerning trend of credential theft through seemingly legitimate developer tools.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data