Mark RadarMARK RADAR
About
EN
Sign in

Malicious JetBrains Marketplace Plugins Steal AI Service API Keys

1 reports · First detected 2026-06-17 · Last active 2026-06-17

JetBrains Marketplace is a key channel for developers to extend the functionality of their integrated development environments. AI coding-assistant plugins typically require access to API keys for services including OpenAI, SiliconFlow and DeepSeek. Stolen keys could be used for unauthorized API calls, incur additional charges and compromise the security of corporate code and development environments.

Cybersecurity company Aikido recently disclosed that at least 15 malicious plugins on the marketplace, disguised as AI coding assistants, steal API keys when users save their settings and transmit them to servers controlled by the attackers. The plugins had nearly 70,000 installations in total. Some also operated paid schemes that provided working keys to paying users. Their exact listing dates and fees have not been disclosed.

All Coverage

1 original reports

The Backstory

The history behind this event

This is the first time the radar has seen this story

See the “Security Vulnerabilities” timeline →
Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)