Malicious plugins on the JetBrains Marketplace have been discovered, with at least 15 plugins identified as capable of stealing artificial intelligence API keys. These plugins masquerade as AI coding assistants, leveraging large language models like DeepSeek to offer various services such as code review and bug finding. The plugins are part of a coordinated malware campaign, and their presence on the marketplace poses a significant threat to developers who use them. The campaign's ability to capture chatbot chats using Chrome extensions further exacerbates the issue, allowing attackers to intercept sensitive information1. The fact that state-aligned activity is involved shifts the threat model, making it a geopolitical concern rather than just a criminal one. This matters to practitioners because it requires a different approach to security, one that takes into account the complexities of state-sponsored threats.
Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
⚠️ Critical Alert
Why This Matters
State-aligned activity involving Intel shifts the threat model from criminal to geopolitical — different playbook required.
References
- The Hacker News. (2026, June 17). Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats. *The Hacker News*. https://thehackernews.com/2026/06/malicious-jetbrains-plugins-steal-ai.html
Original Source
The Hacker News
Read original →