Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft Confirms Defender RoguePlanet 0-Day Exploit Working
June 18, 2026
OpenBSD Vulnerability Lets Attackers Bypass PAP Authentication
June 17, 2026
Stop URL Phishing: Cut SOC Triage Time & Draining SOCs
June 17, 2026
Home/CyberSecurity News/Malicious JetBrains IDE Plugins Steal 70 Multiple Installs
CyberSecurity News

Malicious JetBrains IDE Plugins Steal 70 Multiple Installs

A significant malware campaign has been detected on the JetBrains Marketplace, leveraging at least 15 malicious IDE plugins to steal sensitive API keys from developers. These plugins, downloaded over...

Jennifer sherman
Jennifer sherman
June 17, 2026 3 Min Read
6 0

A significant malware campaign has been detected on the JetBrains Marketplace, leveraging at least 15 malicious IDE plugins to steal sensitive API keys from developers.

These plugins, downloaded over 70,000 times, were published under seven different vendor accounts and disguised as legitimate AI-powered coding assistants.

According to Aikido’s research, the malicious plugins claimed to offer useful developer features such as AI chat, code generation, bug detection, commit message creation, and unit test writing.

They appeared functional and delivered the promised features, making them difficult to detect. However, behind the scenes, they were silently harvesting users’ API keys.

JetBrains Plugins Caught Stealing AI Keys

Aikido researchers found that all identified plugins share a nearly identical codebase that has been slightly modified and republished under different names. To use these tools, developers must enter API keys for services such as OpenAI, DeepSeek, or SiliconFlow.

Once the user enters the API key and clicks “Apply,” the plugin immediately captures and exfiltrates the key without any warning or consent.

The malicious logic is embedded in the plugin’s settings handler, enabling instant, invisible data theft. The stolen API keys are sent via an HTTP POST request to a hardcoded command-and-control (C2) server located at 39.107.60[.]51.

The communication occurs over plaintext HTTP, exposing sensitive credentials to interception and misuse.

The plugins also include a paid tier, which raises further concerns. After users make a payment, the plugin receives a new API key from the attacker-controlled server. It begins using it instead of the user’s original key.

Aikido suggests this may indicate a resale scheme, where stolen API keys from victims are redistributed to paying users. This allows attackers to monetize both stolen credentials and paid subscriptions while shifting operational costs to unsuspecting victims.

The campaign dates back to October 2025, with new malicious plugins continuing to appear as recently as June 2026.

Aikido noted that the actual impact may be higher than reported, as download counts can be manipulated and fake positive reviews were observed on plugin listings.

Integrated Development Environments (IDEs) are increasingly targeted in supply chain attacks because they hold highly sensitive data.

These include source code, credentials, signing keys, and now AI service API keys. Plugins typically run with high privileges and are trusted by developers, making them an ideal vector for stealthy attacks.

Even with JetBrains’ manual review process, small hidden malicious functions can evade detection.

Indicators of Compromise (IOCs)

C2 Server

  • 39.107.60[.]51

Affected Plugins

  • DeepSeek Junit Test (org.sm.yms.toolkit) – 1,121 downloads
  • DeepSeek Git Commit (com.json.simple.kit) – 1,894 downloads
  • DeepSeek FindBugs (org.bug.find.tools) – 1,485 downloads
  • DeepSeek AI Chat (org.translate.ai.simple) – 1,317 downloads
  • DeepSeek Dev AI (com.yy.test.ai.simple) – 740 downloads
  • DeepSeek AI Coding (com.dev.ai.toolkit) – 450 downloads
  • AI FindBugs (com.json.view.simple) – 623 downloads
  • AI Git Commitor (com.my.git.ai.kit) – 301 downloads
  • AI Coder Review (org.check.ai.ds) – 735 downloads
  • DeepSeek Coder AI (com.review.tool.code) – 3,498 downloads
  • AI Coder Assistant (org.code.assist.dev.tool) – 319 downloads
  • DeepSeek Code Review (com.coder.ai.dpt) – 278 downloads
  • CodeGPT AI Assistant (com.my.code.tools) – 25,571 downloads
  • DeepSeek AI Assist (ord.cp.code.ai.kit) – 27,727 downloads
  • Coding Simple Tool (com.dp.git.ai.tool) – 3,931 downloads

Vendor Accounts

  • CodePilot (mycode)
  • StackSmith (misshewei)
  • CodeCrafter (keteme)
  • CodeWeaver (simpledev)
  • JetCode (skyblue)
  • DailyCode (dialycode)
  • ZenCoder (947cb4c8-5db1-4cf0-8182-0aae7c433bb3)

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Mitigations

Aikido recommends that developers immediately remove any affected plugins and revoke exposed API keys. It is critical to rotate credentials and monitor for unusual API usage or billing spikes.

Security experts recommend treating IDE plugins as high-risk dependencies. Avoid entering sensitive credentials into unverified tools and rely only on trusted publishers.

Organizations should also deploy endpoint monitoring solutions and software supply chain security tools to detect malicious packages early and prevent compromise.

This campaign highlights the growing risk of developer-focused attacks and the importance of vigilance when integrating third-party tools into development environments.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

ErrTraffic MaaS Uses Fake CAPTCHAs Cloudflare Turnstile

Next Post

FishMonger Expands SprySOCKS Backdoor Hackers From

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Exploit ClickFix Prompt for MSI & Hands- Install Package
June 17, 2026
GitBait Phishing Abuses GitHub Pages to Attack Banks
June 17, 2026
Fake macOS Updates Steal Passwords & Crypto Hackers Software
June 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us