# Developer Tools Weaponized: How a Coordinated Malware Campaign Turned JetBrains Plugins into AI Key Thieves


A sophisticated, ongoing supply chain attack has compromised the JetBrains Marketplace with at least 15 malicious plugins designed to masquerade as AI coding assistants while systematically stealing API keys from developers. The campaign, which has been active since October 2025 and continues to release new variants, represents a deliberate pivot by threat actors toward infiltrating developer environments where high-value credentials reside.


Researchers at Aikido Security identified the coordinated operation, which shares a consistent codebase across all discovered variants. The plugins have collectively attracted significant downloads—with two variants, CodeGPT AI Assistant and DeepSeek AI Assist, each reportedly surpassing 25,000 installations. The attack pattern demonstrates how threat actors are increasingly weaponizing the trust developers place in open-source marketplaces.


## The Threat


The malicious plugins operate with calculated deception. They present themselves as legitimate AI coding assistants powered by DeepSeek or other large language models, offering genuine functionality including chat interfaces, commit message generation, code review capabilities, bug detection, and unit test generation. Users who install these plugins experience exactly what they expect—a working AI assistant integrated into their JetBrains IDE.


However, beneath this functional veneer lies the true attack mechanism. When developers enter their API keys for services like OpenAI, SiliconFlow, or DeepSeek into the plugin settings panel, those credentials are covertly exfiltrated to an attacker-controlled server at 39.107.60[.]51 via unencrypted HTTP requests. The theft occurs silently in the background while the plugin continues operating normally, a technique known as "living in the margins" of legitimate functionality.


The complete list of identified malicious plugins includes:


  • DeepSeek Junit Test (org.sm.yms.toolkit)
  • DeepSeek Git Commit (com.json.simple.kit)
  • DeepSeek FindBugs (org.bug.find.tools)
  • DeepSeek AI Chat (org.translate.ai.simple)
  • DeepSeek Dev AI (com.yy.test.ai.simple)
  • DeepSeek AI Coding (com.dev.ai.toolkit)
  • AI FindBugs (com.json.view.simple)
  • AI Git Commitor (com.my.git.ai.kit)
  • AI Coder Review (org.check.ai.ds)
  • DeepSeek Coder AI (com.review.tool.code)
  • AI Coder Assistant (org.code.assist.dev.tool)
  • DeepSeek Code Review (com.coder.ai.dpt)
  • CodeGPT AI Assistant (com.my.code.tools)
  • DeepSeek AI Assist (ord.cp.code.ai.kit)
  • Coding Simple Tool (com.dp.git.ai.tool)

  • What distinguishes this campaign is not merely the theft mechanism, but its sophisticated monetization model. Several plugins implement a "paid tier" that creates a secondary victim exploitation loop. After a developer pays a small fee through an in-app donation mechanism, the attacker's server transmits a working API key back to the client, which the plugin then uses for model calls instead of the developer's own credentials.


    This creates a paradoxical scenario: legitimate API key owners pay subscription fees to their AI provider, while the attacker collects money from other developers by offering them "free" access using stolen keys. The ecosystem becomes a marketplace for stolen credentials—users purchasing access to compromised APIs that belong to victims who have no idea their keys have been compromised.


    ## Background and Context


    The attack campaign emerged in late October 2025, but threat actors continue deploying fresh variants as recently as June 10, 2026—suggesting the operation remains active and profitable. The choice to target the JetBrains Marketplace is strategic; the IDE is ubiquitous among professional developers, and its plugin ecosystem, while generally well-maintained, remains a permeable boundary for sophisticated attackers.


    This operation exemplifies a broader threat trend: the deliberate targeting of developer supply chains. Over the past 18-24 months, malicious actors have shifted focus from end-user applications to developer tools and repositories. This pivot reflects a fundamental economic calculus: compromising a single developer can expose entire organizations' infrastructure, source code, deployment credentials, and cloud access keys.


    The AI service ecosystem has made this even more attractive. Organizations are rapidly integrating AI assistants into their development workflows, often without adequate key management hygiene. Developers, accustomed to convenience, frequently store long-lived API keys in accessible locations—including IDE plugins, local configuration files, and sometimes even version control repositories (despite explicit warnings).


    ## Technical Details


    The attack mechanism, while effective, relies on relatively straightforward techniques. Each plugin requires users to authenticate by providing an API key for their chosen AI provider. This design choice—necessitated by legitimate AI assistant functionality—becomes the Trojan horse for credential theft.


    Upon installation and first use, the plugin collects the API key through the settings interface. The code then executes a hidden exfiltration routine that sends the credential to the attacker's command and control infrastructure at 39.107.60[.]51. Notably, this transmission occurs in plaintext HTTP, not encrypted HTTPS, indicating either confidence in the attacker's network position or indifference to traffic analysis.


    The shared codebase across all 15 variants suggests they were generated from a single template or framework, allowing the operator to rapidly produce new variants when individual plugins face detection or removal. This modular approach enables quick iterations: when one variant gets flagged and removed from the marketplace, a cosmetically different version with a new package ID can be uploaded within hours.


    The "paid tier" functionality adds another layer: after payment, the server returns a valid API key to the client. This key likely originates from the attacker's pool of stolen credentials. The operator has effectively created a services business where:


  • Revenue stream 1: Users pay small fees for access to "free" AI API keys
  • Revenue stream 2: The operator likely resells or shares stolen keys with other threat actors
  • Cost: Zero—legitimate key owners foot the bill for all API usage

  • ## Implications for Organizations


    The discovery of this campaign should prompt immediate action across three stakeholder groups:


    For Individual Developers: Any developer who has installed one of these plugins and entered an AI provider API key should assume that key is compromised. The recommended response is immediate revocation and regeneration of affected keys through the respective AI provider's dashboard.


    For Organizations Using JetBrains IDEs: Security teams should audit plugin deployments across their development environments. Many enterprises with centralized IDE deployments may not have visibility into which plugins individual developers have installed. This campaign underscores the need for plugin allowlisting policies or at minimum, mandatory security review processes before installation.


    For AI Service Providers: OpenAI, DeepSeek, Anthropic, SiliconFlow, and other AI API providers are facing both customer impact and potential liability. The compromised API keys generate usage charges against victim accounts, and the resale of credentials represents copyright and terms-of-service violations. These providers should implement anomalous usage detection, geographic access flagging, and rapid key revocation capabilities.


    ## Concurrent Threat: Chrome Extension Campaign


    The timing of this JetBrains discovery coincides with the identification of a parallel attack vector: malicious Chrome extensions masquerading as ad blockers that capture conversations with AI chatbots. Designated PromptSnatcher by security researchers, these extensions target users of OpenAI ChatGPT, Anthropic Claude, Google Gemini, Microsoft Copilot, Perplexity, DeepSeek, xAI Grok, and Meta AI.


    Rather than targeting credentials, PromptSnatcher focuses on conversation content—potentially capturing sensitive information, proprietary prompts, internal project details, or personal data users discuss with AI assistants. The combination of JetBrains plugin attacks (credential theft) and Chrome extension attacks (conversation theft) suggests coordinated activity or at minimum, parallel threat actors exploiting the same general trust gap around AI tools.


    ## Recommendations


    Immediate Actions:

  • Revoke all AI provider API keys that may have been entered into any JetBrains plugin
  • Audit IDE plugin deployments across your development organization
  • Block identified malicious plugin package IDs at the network or endpoint level
  • Scan development machines for PromptSnatcher or similar Chrome extensions

  • Medium-Term Controls:

  • Implement plugin allowlisting policies in JetBrains IDEs
  • Mandate API key rotation cycles and avoid long-lived credentials
  • Deploy secrets scanning tools in development environments to catch exposed keys
  • Provide security training on supply chain risks in open-source ecosystems

  • Long-Term Strategy:

  • Evaluate passwordless authentication for AI API access where available
  • Adopt credential management tools that reduce human exposure to secrets
  • Implement anomalous usage detection at the API provider level
  • Monitor for similar attacks targeting other IDE marketplaces (Visual Studio Code, Sublime Text)

  • ---


    ## HackWire Analysis


    This campaign reveals a critical inflection point in how threat actors approach developer security. For years, the industry warned about compromised open-source libraries affecting dependency chains. We're now witnessing the natural evolution: attackers targeting the *tools developers use to write code*, not just the code itself.


    What makes this particularly concerning is the *legitimacy theater*. These aren't broken plugins that crash immediately—they work perfectly as advertised. A developer installing CodeGPT AI Assistant receives exactly what's promised: a functional AI coding assistant. The attack is invisible because it piggybacks on legitimate functionality rather than replacing it.


    The monetization model also signals sophistication. By creating a secondary economy around stolen credentials, the operator has transformed theft into a recurring-revenue service. This isn't smash-and-grab—it's a sustainable criminal business model that likely attracts partners. The server at 39.107.60[.]51 may be operating as a credentials clearinghouse, selling access to other threat actors or LLMjacking operations.


    For defenders, the lesson is uncomfortable: marketplaces matter more than ever. JetBrains, Visual Studio Code, and similar plugin ecosystems have become critical infrastructure for developer security. A single compromised plugin reaching 25,000 developers is a nation-state-scale compromise vector. The marketplace operator's security practices—code review, anomaly detection, publisher verification—are now *your* security boundary.


    Organizations should treat plugin marketplaces with the same rigor applied to SaaS vendor assessments. Not every plugin needs to be blocked, but every plugin should be verified by someone with security expertise before it enters your development environment.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)