Malicious JetBrains Marketplace Plugins Steal AI Service API Keys
JetBrains Marketplace is a key channel for developers to extend the functionality of their integrated development environments. AI coding-assistant plugins typically require access to API keys for services including OpenAI, SiliconFlow and DeepSeek. Stolen keys could be used for unauthorized API calls, incur additional charges and compromise the security of corporate code and development environments.
Cybersecurity company Aikido recently disclosed that at least 15 malicious plugins on the marketplace, disguised as AI coding assistants, steal API keys when users save their settings and transmit them to servers controlled by the attackers. The plugins had nearly 70,000 installations in total. Some also operated paid schemes that provided working keys to paying users. Their exact listing dates and fees have not been disclosed.
All Coverage
1 original reportsThe Backstory
The history behind this eventThis is the first time the radar has seen this story
See the “Security Vulnerabilities” timeline →Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →