Malicious JetBrains Plugins Steal AI API Keys

🟠 High | Source: The Hacker News Attackers published at least 15 malicious plugins to the JetBrains Marketplace, disguising them as AI coding assistants powered by DeepSeek and similar models. These plugins silently steal API keys for AI services such as OpenAI, Anthropic, and others from developers’ machines. A related wave of malicious Chrome extensions is also capturing conversations from AI chatbot interfaces, broadening the attack surface. Security Architect’s Take: Audit all JetBrains plugins installed across your engineering fleet immediately and remove any AI assistant plugins not sourced from a verified, internal allowlist. Enforce secrets scanning in CI/CD pipelines and rotate any AI provider API keys that may have been exposed on developer workstations, treating them as compromised until confirmed otherwise. ...

17 June 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. Learn more