Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Aikido Security identified 15 malicious plugins on the JetBrains Marketplace that pose as AI coding assistants built on DeepSeek and other LLMs, exfiltrating user-entered API keys for OpenAI, SiliconFlow, and DeepSeek to an attacker-controlled server at IP 39.107.60[.]51 over plaintext HTTP.
- The JetBrains campaign has been active since late October 2025, with new plugins released as recently as June 10, 2026; two plugins — CodeGPT AI Assistant and DeepSeek AI Assist — each show over 25,000 downloads, though Aikido notes the counts may be inflated to fake popularity.
- The JetBrains plugins implement a paid tier where users pay a small donation fee and receive a working API key back, suggesting the operators are monetizing stolen credentials by reselling access to victims' paid AI services while the legitimate key owners pay the bill.
- Researcher Jean-Marie R. uncovered a separate operation codenamed PromptSnatcher involving two Chrome extensions — "Smart Adblocker" (90,000 users, published October 2022) and "Adblock for Browser" (10,000 users, published August 2023) — that capture conversation data from ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek, Grok, and Meta AI.
- The Chrome extensions use legitimate public filter lists (EasyList, IDCAC) as cover for a custom interception engine that records full conversation history, model usage, and account-tier metadata, transmitting the data to operator-controlled infrastructure under a generic "Enhanced Protection" consent string.
- Both extensions are still available on the Chrome Web Store, and the AI-data exfiltration features appear to have been introduced as software updates to extensions that have existed for years, making the PromptSnatcher attack part of a growing category called "Prompt Poaching."
- Aikido researcher Ilyas Makari said the JetBrains campaign is further evidence that threat actors are increasingly targeting developer environments through open-source ecosystems, where source code, cloud credentials, signing keys, and paid AI API keys can be resold for LLMjacking schemes.
Why it matters: Developers who entered API keys into these 15 JetBrains plugins are unknowingly funding a resale scheme — the operator collects user fees while the original key holder pays for all the AI usage, Aikido warned. Meanwhile, roughly 100,000 Chrome users of the two fake ad blockers have had their AI conversations — potentially including proprietary code or sensitive business prompts — siphoned to unknown operators, with both extensions still live on the Chrome Web Store.




