<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Chrome-Extensions on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/chrome-extensions/</link><description>Recent content in Chrome-Extensions on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Tue, 17 Jun 2025 13:51:58 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/chrome-extensions/index.xml" rel="self" type="application/rss+xml"/><item><title>Malicious JetBrains Plugins Steal AI API Keys</title><link>https://zxcloudsecurity.co.uk/posts/malicious-jetbrains-plugins-steal-ai-api-keys-supply-chain/</link><pubDate>Wed, 17 Jun 2026 13:51:58 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/malicious-jetbrains-plugins-steal-ai-api-keys-supply-chain/</guid><description>15 malicious JetBrains Marketplace plugins disguised as AI coding assistants are stealing AI API keys. Chrome extensions also capture chatbot conversations</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/malicious-jetbrains-plugins-steal-ai.html">The Hacker News</a></p>
<hr>
<p>Attackers published at least 15 malicious plugins to the JetBrains Marketplace, disguising them as AI coding assistants powered by DeepSeek and similar models. These plugins silently steal API keys for AI services such as OpenAI, Anthropic, and others from developers&rsquo; machines. A related wave of malicious Chrome extensions is also capturing conversations from AI chatbot interfaces, broadening the attack surface.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit all JetBrains plugins installed across your engineering fleet immediately and remove any AI assistant plugins not sourced from a verified, internal allowlist. Enforce secrets scanning in CI/CD pipelines and rotate any AI provider API keys that may have been exposed on developer workstations, treating them as compromised until confirmed otherwise.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/malicious-jetbrains-plugins-steal-ai.html">Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats</a></p>
]]></content:encoded></item></channel></rss>