Multiple JetBrains IDE plugins caught stealing AI keys
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A coordinated malware campaign has been discovered on the JetBrains Marketplace involving at least 15 IDE plugins published under seven vendor accounts, collectively installed nearly 70,000 times. Each plugin poses as an AI coding assistant (built on DeepSeek and similar LLMs) but silently exfiltrates any AI provider API key (OpenAI, DeepSeek, SiliconFlow) entered in its settings to a hardcoded attacker-controlled server over plain HTTP. The stolen keys are likely resold to paying users of the same plugins, creating a scheme where victims unknowingly fund others' AI compute. The campaign has been active since October 2025 with new plugins still appearing in June 2026. A full list of affected plugin IDs, vendor accounts, and the C2 server IP are provided as indicators of compromise.
Table of contents
How the theft worksWhy attackers keep aiming at IDEsHow Aikido detects thisIndicators of Compromise62.2K Impressions3 Comments