# Malicious JetBrains Plugins Exfiltrate AI API Keys From 70,000 Developers in Coordinated Campaign


A coordinated malware campaign has compromised at least 70,000 developers through 15 deceptively legitimate plugins on the JetBrains Marketplace, according to security researchers at Aikido Security. The plugins—masquerading as AI coding assistants and development utilities—silently exfiltrate API credentials for popular AI services including OpenAI, DeepSeek, and SiliconFlow, representing a novel vector for credential theft targeting the developer ecosystem.


## The Threat: A Hidden Exfiltration Campaign


The malicious plugins function exactly as advertised: they provide legitimate AI-powered features like code review, Git commit assistance, and bug detection. However, they simultaneously steal API credentials stored in the plugin settings and transmit them to attacker-controlled infrastructure. The campaign, first detected in October 2025, demonstrates sustained operational activity, with new malicious plugins continuing to be published through June 2026.


According to Aikido's analysis, the theft occurs at the moment a user clicks "Apply" after entering an API key into the plugin settings. The credential is immediately exfiltrated to a hardcoded command-and-control server at 39.107.60[.]51 over unencrypted HTTP.


Key indicators of the campaign:


  • At least 15 plugins published under seven distinct vendor accounts
  • Combined installation count exceeds 70,000 (though exact unique installations unknown)
  • Code signatures shared across all plugins indicate coordinated development
  • Active distribution period: October 2025 through June 2026
  • Most downloaded variants: DeepSeek AI Assist (27,727 installations) and CodeGPT AI Assistant (25,571 installations)

  • ## How the Attack Works: Technical Architecture


    The attack chain is remarkably straightforward but effective. Developers, seeking to leverage AI in their IDE, install plugins that appear to integrate legitimate AI services. The plugins request the developer's API keys—a necessary and expected step for authenticated access to AI APIs like OpenAI's GPT models or SiliconFlow's inference endpoints.


    The exfiltration mechanism:


    1. User enters API key into plugin settings

    2. User clicks "Apply" to save configuration

    3. Plugin transmits credential to hardcoded attacker server (HTTP, unencrypted)

    4. Attacker-controlled server receives and stores credential

    5. Plugin continues functioning normally, creating no suspicious behavior


    Independent analysis by BleepingComputer confirmed the credential theft code persists in recent plugin versions. Notably, at the time of discovery, several affected plugins remained available for download directly from the official JetBrains Marketplace, indicating a gap in review or remediation processes.


    ## The Campaign Roster: 15 Plugins Across Seven Accounts


    The Aikido research team documented the complete list of compromised plugins, revealing a sophisticated distribution strategy designed to appear as separate, unrelated tools:


    | Plugin Name | Plugin ID | Known Downloads |

    |---|---|---|

    | DeepSeek AI Assist | ord.cp.code.ai.kit | 27,727 |

    | CodeGPT AI Assistant | com.my.code.tools | 25,571 |

    | DeepSeek AI Coding | com.dev.ai.toolkit | — |

    | DeepSeek Dev AI | com.yy.test.ai.simple | — |

    | DeepSeek AI Chat | org.translate.ai.simple | — |

    | AI Coder Review | org.check.ai.ds | — |

    | DeepSeek Code Review | com.coder.ai.dpt | — |

    | AI Coder Assistant | org.code.assist.dev.tool | — |

    | AI Git Commitor | com.my.git.ai.kit | — |

    | AI FindBugs | com.json.view.simple | — |

    | DeepSeek Git Commit | com.json.simple.kit | — |

    | DeepSeek FindBugs | org.bug.find.tools | — |

    | DeepSeek Junit Test | org.sm.yms.toolkit | — |

    | DeepSeek Coder AI | com.review.tool.code | — |

    | Coding Simple Tool | com.dp.git.ai.tool | — |


    All 15 plugins share remarkably similar code signatures, suggesting they were compiled from a common malicious codebase and repackaged under different names to evade detection and maximize distribution reach.


    ## The Monetization Model: "Paid Tier" Credential Laundering


    The most unsettling aspect of this campaign is the apparent monetization scheme uncovered by Aikido. Beyond simple credential theft, the attacker infrastructure implements a "paid tier" system: users who donate money through a payment wall built into the plugin receive *working API credentials* from the attackers' command-and-control server.


    This suggests a laundering pipeline: stolen API keys from free-tier users are harvested, aggregated, and redistributed to paid customers. The scheme is economically perverse—legitimate AI providers would never hand unrestricted API keys to random users—but profitable for attackers managing a pooled credential inventory. This model also masks the financial trail; users believe they're purchasing legitimate API access rather than stolen credentials.


    The implication is troubling: paid plugin users may unknowingly be consuming stolen API quotas, potentially exhausting victims' rate limits or incurring unexpected charges.


    ## Industry Context: Why JetBrains Plugins?


    Developer tools represent a high-value attack surface for several reasons:


  • High-privilege environment: IDEs operate with extensive system access, making them ideal distribution points for malware
  • Credential concentration: Developers store multiple sensitive credentials (API keys, authentication tokens, cloud provider credentials) in plugin configurations
  • Marketplace trust: The JetBrains Marketplace benefits from perceived security vetting, lowering user skepticism
  • AI adoption surge: The rapid proliferation of AI coding assistants has created massive demand and incentive for users to install new plugins without deep scrutiny
  • Infrequent audits: Unlike npm or PyPI, JetBrains Marketplace reports of malicious packages remain relatively rare, suggesting fewer researchers actively monitoring

  • The targeting of AI API keys specifically reflects attackers' understanding of current developer workflows: AI coding assistants (OpenAI, DeepSeek, SiliconFlow) are rapidly becoming standard tools, and developers often store high-value credentials for these services in readily accessible plugin settings.


    ## Implications for Organizations and Developers


    The impact of this campaign extends beyond individual developers:


    For organizations:

  • Developers using personal or enterprise JetBrains licenses may have corporate AI API keys compromised
  • Attackers gain access to AI inference quotas, potentially incurring unauthorized charges to corporate accounts
  • Compromised credentials may provide initial access for follow-on attacks targeting internal systems
  • Organizations relying on third-party IDE plugins lack visibility into credential exposure

  • For AI providers:

  • OpenAI, DeepSeek, and SiliconFlow face API quota consumption and potential reputation damage if their stolen credentials are used for malicious purposes
  • Rate limiting and usage monitoring become urgent priorities to detect anomalous access patterns

  • For JetBrains:

  • The discovery raises questions about Marketplace vetting processes and whether security reviews are conducted before publication
  • The persistence of malicious plugins suggests slow or absent incident response once threats are identified

  • ## Recommendations for Developers and Organizations


    Immediate actions:


  • Rotate all AI API keys stored in JetBrains IDE plugins
  • Audit plugin installations: Review the list of installed plugins against the campaign roster (provided above)
  • Monitor for unauthorized usage: Check API billing dashboards for unexpected charges or rate limit hits
  • Uninstall affected plugins immediately

  • Medium-term:


  • Migrate to environment variables: Store sensitive credentials in environment variables rather than plugin settings, where they're less exposed to malicious plugins
  • Use API key scoping: Many AI providers (OpenAI, etc.) support limited-scope API keys—configure keys with minimal required permissions
  • Enable API access logging: Monitor which IPs and user agents are consuming your API quotas
  • Review plugin policies: Organizations should establish policies restricting IDE plugin installations to a curated allowlist

  • Long-term:


  • Pressure for plugin vetting: Advocate for stronger security review processes in the JetBrains Marketplace
  • Support plugin signing: Ecosystem-level solutions like signed plugins with cryptographic verification could reduce trust-based attacks
  • Diversify credential storage: Use secrets management systems (1Password, HashiCorp Vault, AWS Secrets Manager) rather than IDE configuration files

  • ---


    ## HackWire Analysis


    This campaign represents a maturation of supply-chain attacks targeting developer tools. Previous waves targeted npm, PyPI, and RubyGems—repositories where volume attacks are easier due to loose vetting. The JetBrains Marketplace campaign demonstrates that attackers are now willing to invest in quality-over-volume strategies, building genuinely useful plugins that *actually work* while silently exfiltrating credentials.


    The "paid tier" monetization model is particularly revealing. Rather than viewing stolen credentials as pure inventory, the attackers have built a business layer—turning credential theft into a subscription service. This signals a shift from one-off cybercriminals toward organized, sustained operations with business discipline.


    What's dangerous is the trust asymmetry: JetBrains plugins receive far less scrutiny than npm packages because the Marketplace is smaller and feels "safer." The community hasn't yet developed the paranoia about IDE plugins that it has about package managers. That's changing now, but the lag matters. An estimated 70,000 developers have already been compromised, and each one represents potential follow-on attacks against their employers.


    The real kicker: JetBrains apparently took days or weeks to remove plugins *after* public disclosure. For a company with the resources JetBrains commands, that's inexcusable. The message to attackers is clear: if you get past initial review, you've got weeks of operational runway before removal.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)