# Malicious JetBrains Plugins Exfiltrate AI API Keys From 70,000 Developers in Coordinated Campaign
A coordinated malware campaign has compromised at least 70,000 developers through 15 deceptively legitimate plugins on the JetBrains Marketplace, according to security researchers at Aikido Security. The plugins—masquerading as AI coding assistants and development utilities—silently exfiltrate API credentials for popular AI services including OpenAI, DeepSeek, and SiliconFlow, representing a novel vector for credential theft targeting the developer ecosystem.
## The Threat: A Hidden Exfiltration Campaign
The malicious plugins function exactly as advertised: they provide legitimate AI-powered features like code review, Git commit assistance, and bug detection. However, they simultaneously steal API credentials stored in the plugin settings and transmit them to attacker-controlled infrastructure. The campaign, first detected in October 2025, demonstrates sustained operational activity, with new malicious plugins continuing to be published through June 2026.
According to Aikido's analysis, the theft occurs at the moment a user clicks "Apply" after entering an API key into the plugin settings. The credential is immediately exfiltrated to a hardcoded command-and-control server at 39.107.60[.]51 over unencrypted HTTP.
Key indicators of the campaign:
## How the Attack Works: Technical Architecture
The attack chain is remarkably straightforward but effective. Developers, seeking to leverage AI in their IDE, install plugins that appear to integrate legitimate AI services. The plugins request the developer's API keys—a necessary and expected step for authenticated access to AI APIs like OpenAI's GPT models or SiliconFlow's inference endpoints.
The exfiltration mechanism:
1. User enters API key into plugin settings
2. User clicks "Apply" to save configuration
3. Plugin transmits credential to hardcoded attacker server (HTTP, unencrypted)
4. Attacker-controlled server receives and stores credential
5. Plugin continues functioning normally, creating no suspicious behavior
Independent analysis by BleepingComputer confirmed the credential theft code persists in recent plugin versions. Notably, at the time of discovery, several affected plugins remained available for download directly from the official JetBrains Marketplace, indicating a gap in review or remediation processes.
## The Campaign Roster: 15 Plugins Across Seven Accounts
The Aikido research team documented the complete list of compromised plugins, revealing a sophisticated distribution strategy designed to appear as separate, unrelated tools:
| Plugin Name | Plugin ID | Known Downloads |
|---|---|---|
| DeepSeek AI Assist | ord.cp.code.ai.kit | 27,727 |
| CodeGPT AI Assistant | com.my.code.tools | 25,571 |
| DeepSeek AI Coding | com.dev.ai.toolkit | — |
| DeepSeek Dev AI | com.yy.test.ai.simple | — |
| DeepSeek AI Chat | org.translate.ai.simple | — |
| AI Coder Review | org.check.ai.ds | — |
| DeepSeek Code Review | com.coder.ai.dpt | — |
| AI Coder Assistant | org.code.assist.dev.tool | — |
| AI Git Commitor | com.my.git.ai.kit | — |
| AI FindBugs | com.json.view.simple | — |
| DeepSeek Git Commit | com.json.simple.kit | — |
| DeepSeek FindBugs | org.bug.find.tools | — |
| DeepSeek Junit Test | org.sm.yms.toolkit | — |
| DeepSeek Coder AI | com.review.tool.code | — |
| Coding Simple Tool | com.dp.git.ai.tool | — |
All 15 plugins share remarkably similar code signatures, suggesting they were compiled from a common malicious codebase and repackaged under different names to evade detection and maximize distribution reach.
## The Monetization Model: "Paid Tier" Credential Laundering
The most unsettling aspect of this campaign is the apparent monetization scheme uncovered by Aikido. Beyond simple credential theft, the attacker infrastructure implements a "paid tier" system: users who donate money through a payment wall built into the plugin receive *working API credentials* from the attackers' command-and-control server.
This suggests a laundering pipeline: stolen API keys from free-tier users are harvested, aggregated, and redistributed to paid customers. The scheme is economically perverse—legitimate AI providers would never hand unrestricted API keys to random users—but profitable for attackers managing a pooled credential inventory. This model also masks the financial trail; users believe they're purchasing legitimate API access rather than stolen credentials.
The implication is troubling: paid plugin users may unknowingly be consuming stolen API quotas, potentially exhausting victims' rate limits or incurring unexpected charges.
## Industry Context: Why JetBrains Plugins?
Developer tools represent a high-value attack surface for several reasons:
The targeting of AI API keys specifically reflects attackers' understanding of current developer workflows: AI coding assistants (OpenAI, DeepSeek, SiliconFlow) are rapidly becoming standard tools, and developers often store high-value credentials for these services in readily accessible plugin settings.
## Implications for Organizations and Developers
The impact of this campaign extends beyond individual developers:
For organizations:
For AI providers:
For JetBrains:
## Recommendations for Developers and Organizations
Immediate actions:
Medium-term:
Long-term:
---
## HackWire Analysis
This campaign represents a maturation of supply-chain attacks targeting developer tools. Previous waves targeted npm, PyPI, and RubyGems—repositories where volume attacks are easier due to loose vetting. The JetBrains Marketplace campaign demonstrates that attackers are now willing to invest in quality-over-volume strategies, building genuinely useful plugins that *actually work* while silently exfiltrating credentials.
The "paid tier" monetization model is particularly revealing. Rather than viewing stolen credentials as pure inventory, the attackers have built a business layer—turning credential theft into a subscription service. This signals a shift from one-off cybercriminals toward organized, sustained operations with business discipline.
What's dangerous is the trust asymmetry: JetBrains plugins receive far less scrutiny than npm packages because the Marketplace is smaller and feels "safer." The community hasn't yet developed the paranoia about IDE plugins that it has about package managers. That's changing now, but the lag matters. An estimated 70,000 developers have already been compromised, and each one represents potential follow-on attacks against their employers.
The real kicker: JetBrains apparently took days or weeks to remove plugins *after* public disclosure. For a company with the resources JetBrains commands, that's inexcusable. The message to attackers is clear: if you get past initial review, you've got weeks of operational runway before removal.
— HackWire Editorial
---
## Related Coverage