BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Malicious JetBrains Plugins Steal AI Keys

Malicious plugins and extensions steal AI API keys and user conversations targeting developers.

  • Fifteen malicious plugins on the JetBrains Marketplace have been stealing AI provider API keys in a campaign active since October 2025.
  • Two of the fraudulent plugins, CodeGPT AI Assistant and DeepSeek AI Assist, have been downloaded over 25,000 times each, according to Aikido Security.
  • Separately, two Chrome ad blocker extensions with over 100,000 combined users have been covertly stealing user conversations with major AI chatbots.
  • The operations highlight a growing trend of threat actors targeting developers and users to steal valuable AI credentials and data.

Cybersecurity researchers have uncovered a coordinated malware campaign on the JetBrains Marketplace involving fifteen malicious plugins designed to steal AI provider keys. This ongoing threat, which began in late 2025, has successfully targeted developers through seemingly functional AI coding assistants.

- Advertisement -

Aikido Security researcher Ilyas Makari detailed that the plugins, posing as tools from DeepSeek and others, covertly exfiltrate user-entered API keys. The stolen keys are sent to a remote attacker-controlled server in plaintext, “while the genuine key owners pay the bill.”

Consequently, the campaign may operate as an illicit monetization scheme where stolen keys are shared. This activity exemplifies how threat actors are increasingly targeting developer environments for valuable secrets.

Meanwhile, a separate operation codenamed PromptSnatcher has been stealing AI chatbot conversations via malicious Chrome extensions. Two ad blocker extensions with a combined 100,000 users have been intercepting private chats from platforms like ChatGPT and Gemini.

These Prompt Poaching attacks capture full conversation histories and model usage data without clear user consent. The discovery underscores the expanding threat landscape targeting AI services and their users directly.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Senate GOP Updated Clarity Act Targets Fake DeFi, Vote Set

Senate Republicans released an updated Clarity Act on Thursday targeting non-decentralized crypto trading protocols.The...

TSMC revenue hits record $16.3B, AI demand fuels 53% jump

TSMC reported a record August revenue of NT$514.8 billion ($16.3 billion), marking a 53.3%...

AI Leaves Banks Minutes to Fix Flaws: BIS

A BIS paper warns that AI is shortening the time banks have to repair...

US housing split: low-end sales down, luxury up on AI wealth

Compass CEO Robert Reffkin says U.S. housing market is splitting: low-end sales down 10%...

Trezor email partner breach exposes 347K users to phishing

Trezor's third-party email partner Brevo was breached, exposing 347,000 newsletter subscribers' email addresses.Hackers used...

Must Read

8 Best Bitcoin Offshore Hosting Providers

In this blog post, we'll list the top 8 best bitcoin offshore hosting providers that accept Bitcoin and other cryptocurrencies.As Bitcoin continues to grow...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading