At least 15 malicious plugins found on the JetBrains Marketplace were designed to steal AI API keys from developers.
The campaign, discovered by Aikido Security, includes plugins that act as AI coding assistants, code-review tools, and Git utilities powered by popular AI services such as OpenAI, DeepSeek, and SiliconFlow.
“We detected a coordinated malware campaign on the JetBrains Marketplace,” warns Aikido.
“At least 15 IDE plugins, published under seven vendor accounts, share the same hidden behavior. Each one exfiltrates the AI provider API key that you stored into its settings, and together they have been installed close
We don’t just report the news, we deliver it through the voices of multiple expert staff writers, each selected to broaden our scope and deepen our storytelling.



