A coordinated campaign on the JetBrains Marketplace used at least 15 malicious IDE plugins masquerading as AI coding assistants to steal developers’ API keys for services including OpenAI, DeepSeek, and SiliconFlow. Researchers said the extensions appeared legitimate and functional, but silently exfiltrated credentials entered by users to attacker-controlled infrastructure, turning trusted development tools into a credential-harvesting channel.
The plugins were reportedly installed about 70,000 times and were active from at least October 2025 through June 2026. Investigators linked the operation to fake assistant-style extensions and said the actor may have monetized the theft by reselling stolen API access; some plugins allegedly included a paid tier that appeared to return API keys sourced from other victims, suggesting the campaign blended credential theft with a marketplace for illicit API access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Aikido Security disclosed that multiple JetBrains Marketplace plugins were stealing AI-related API keys from developers and published indicators of compromise for the campaign. The researchers said the plugins appeared functional but silently forwarded entered keys to attacker-controlled infrastructure.
According to Aikido Security, the campaign remained active through June 2026, with the most recent identified malicious JetBrains Marketplace plugins released that month. In total, at least 15 plugins were identified and had accumulated about 70,000 installs.
Aikido Security reported that the earliest identified plugins in the campaign dated back to October 2025. These plugins impersonated AI coding assistants while later being found to exfiltrate developers' AI-service API keys.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.