Malicious JetBrains Marketplace plugins steal AI API keys from developers - BleepingComputer

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- JetBrains Marketplace is hosting at least 15 malicious plugins caught stealing developers' API keys for AI services including DeepSeek and OpenAI, per Hackread's tally.
- The malicious plugin campaign is linked to over 70,000 combined installs according to gbhackers.com, suggesting broad reach before detection.
- Targeted AI providers named across coverage include DeepSeek and OpenAI, putting developers using those APIs at direct credential-theft risk.
Why it matters: Developers who installed the compromised JetBrains plugins may have had their DeepSeek and OpenAI API keys exfiltrated — keys that can be resold or abused to run up compute costs at the victim's expense. The 70,000+ install footprint across just 15 plugins shows how a trusted IDE marketplace can become a supply-chain attack vector for AI credentials.




