Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
A "coordinated malware campaign" that has released at least 15 malicious plugins that can steal artificial intelligence (AI) provider keys has been identified by cybersecurity researchers on the JetBrains Marketplace.
According to Aikido Security researcher Ilyas Makari, each plugin poses as an AI coding helper based on DeepSeek and other large language models, providing chat, commit messages, code review, issue discovery, and unit tests. They work just as promised. Nevertheless, the AI provider API key you input is exfiltrated to a server under the attacker's control.
According to reports, the activity began around the end of October 2025, and as recently as June 10, 2026, fresh plugins were made available. There are more than 25,000 downloads of two of the plugins, CodeGPT AI Assi...





