Last updated 1 month ago
JetBrains, a Czech technology company known for its integrated development environments (IDEs), disclosed that at least 15 malicious plugins were discovered on its JetBrains Marketplace. The plugins were designed to steal AI API keys from developers. The disclosure was made on June 17, 2026, but the exact discovery date is not specified in the article.
The attack vector was a supply chain compromise, where threat actors uploaded malicious plugins to the official JetBrains Marketplace. These plugins targeted developers by exfiltrating AI API keys, which could be used to access and abuse AI services. The specific techniques used to hide the malicious code within the plugins are not detailed, but the attack exploited the trust developers place in the official marketplace.
No further post-incident details are provided in the article, such as regulatory involvement, litigation, or remediation steps. The article focuses on the discovery and warning to developers about the malicious plugins.
Malicious plugins on JetBrains Marketplace designed to steal AI API keys
This incident highlights the critical need for rigorous vetting and continuous monitoring of third-party plugins in software marketplaces. JetBrains, as a technology company, must implement automated scanning and manual review processes to detect malicious code before it reaches developers. Developers should also verify plugin authenticity and limit API key exposure to trusted sources.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector