step-security · Crawled Jul 5, 2026
15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers
4 IoCs
Read original article ↗
AI Summary
A coordinated supply chain attack spanning eight months involved 15 malicious JetBrains plugins that stole AI API keys from approximately 70,000 developers. The plugins, masquerading as legitimate AI coding assistants, exfiltrated OpenAI, DeepSeek, and SiliconFlow API keys to a command-and-control server in Beijing. The stolen credentials were transmitted in plaintext over HTTP, and the attacker's infrastructure remains active despite JetBrains' removal of the plugins and banning of associated accounts.
AI-extracted · verify before operational use