Back to feed
Dev.to
Dev.to
6/17/2026
JetBrains Marketplace Supply Chain Attack: 15 Malicious AI Plugins & API Key Exfiltration

JetBrains Marketplace Supply Chain Attack: 15 Malicious AI Plugins & API Key Exfiltration

Short summary

Security researchers discovered 15 malicious JetBrains plugins masquerading as DeepSeek AI assistants, exfiltrating developer API keys (OpenAI, Anthropic, Gemini) and LLM chat transcripts. The attack exploits developer trust in marketplace vetting and automatic IDE plugin permissions to harvest credentials and establish persistence. Attackers validate stolen keys immediately and can impersonate developers across AI provider accounts, accessing sensitive conversations and proprietary code reviews.

  • 15 malicious JetBrains marketplace plugins pose as AI coding assistants while harvesting API keys and LLM conversation transcripts
  • Attack leverages developer trust in IDE marketplace curation and auto-granted plugin permissions to establish persistence
  • Stolen credentials immediately validated by attackers; can impersonate developers and access sensitive proprietary code and architecture discussions

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more