Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
News Source : Internet
News Summary
- Researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace.
- The malicious plugins are capable of exfiltrating artificial intelligence (AI) provider keys.
- The activity is said to have been ongoing since the end of October 2025, with new plugins released as recently as June 10, 2026.
- Two of the plugins, CodeGPT AI Assistant and DeepSeek AI Assist, have more than 25,000 downloads each, although it's not clear if the counts are authentic or if they have been inflated to fake their popularity.
Never miss a story from us, subscribe to our newsletter