Malicious JetBrains Marketplace plugins steal AI API keys from developers - BleepingComputer
70,000+ developers at risk. Malicious JetBrains plugins are harvesting AI API keys in the wild.

Why it matters
As AI infrastructure becomes critical to developer workflows, supply-chain attacks on IDE plugins represent a new vector for compromising API credentials and model access. This highlights governance gaps in how developers secure AI integrations.
The key facts
5 to know70,000+ installations of malicious JetBrains Marketplace plugins
Attack targets AI API keys from developers
Multiple security outlets reporting (BleepingComputer, gbhackers, Techzine Global)
Supply-chain attack via trusted developer tooling
Published June 16, 2026
Go to the source
Reuters Technologynews.google.com
Publisher excerpt: Malicious JetBrains Marketplace plugins steal AI API keys from developers BleepingComputer JetBrains Plugin Security Alert: 70,000+ Installs Linked to AI Key Theft gbhackers.com JetBrains plug-ins steal API keys from AI services Techzine Global