PulseAugur
EN
LIVE 14:20:04

Malicious JetBrains Plugins Steal AI API Keys

Cybersecurity researchers have identified 15 malicious plugins on the JetBrains Marketplace designed to steal API keys from AI models like DeepSeek and OpenAI. These plugins, which have accumulated nearly 70,000 downloads and employ fake reviews, have been active since October 2025. A separate Chrome extension campaign is also reportedly recording chatbot conversations. AI

IMPACT Developers using AI coding assistants should be vigilant about plugin sources to prevent API key theft and protect sensitive data.

RANK_REASON The cluster describes malicious plugins distributed on a software development platform, which falls under the 'tool' category as it relates to software distribution and security vulnerabilities.

Read on Mastodon — sigmoid.social →

AI-generated summary · Google Gemini · from 2 sources. How we write summaries →

COVERAGE [2]

  1. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    Hackers are using fake AI coding assistants on the # JetBrains Marketplace to steal DeepSeek, OpenAI, and other developer API keys - 15 malicious plugins, nearl

    Hackers are using fake AI coding assistants on the # JetBrains Marketplace to steal DeepSeek, OpenAI, and other developer API keys - 15 malicious plugins, nearly 70K downloads, and fake reviews used to lure developers. Read: https:// hackread.com/malicious-jetbrai ns-plugins-stea…

  2. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    🚨Cybersecurity Alert🚨 Beware of 15 malicious JetBrains plugins! They've been stealthily stealing AI API keys since October 2025! Even popular chatbot conversati

    🚨Cybersecurity Alert🚨 Beware of 15 malicious JetBrains plugins! They've been stealthily stealing AI API keys since October 2025! Even popular chatbot conversations aren't safe with a separate Chrome extension campaign recording them. Update your cybersecurity measures now! 🔒 # Cy…