Dev.to
6/17/2026

JetBrains Marketplace Supply Chain Attack: 15 Malicious AI Plugins & API Key Exfiltration
Short summary
Security researchers discovered 15 malicious JetBrains plugins masquerading as DeepSeek AI assistants, exfiltrating developer API keys (OpenAI, Anthropic, Gemini) and LLM chat transcripts. The attack exploits developer trust in marketplace vetting and automatic IDE plugin permissions to harvest credentials and establish persistence. Attackers validate stolen keys immediately and can impersonate developers across AI provider accounts, accessing sensitive conversations and proprietary code reviews.
- •15 malicious JetBrains marketplace plugins pose as AI coding assistants while harvesting API keys and LLM conversation transcripts
- •Attack leverages developer trust in IDE marketplace curation and auto-granted plugin permissions to establish persistence
- •Stolen credentials immediately validated by attackers; can impersonate developers and access sensitive proprietary code and architecture discussions
Generated with AI, which can make mistakes.
Is this a good recommendation for you?


