JetBrains Plugins Turn AI Keys Into Loot

Trusted IDE extensions can become credential traps. Here the break is not a bad plugin in the abstract. It is the settings box itself: developers enter long-lived AI API keys to make the tool work, and the plugin quietly sends those keys to an attacker-controlled server when they click Apply. Aikido says at least 15 JetBrains Marketplace plugins shared the same hidden behavior across seven vendor accounts, with nearly 70,000 installs and new uploads as late as June 10, 2026. The plugins were designed to look normal and still perform their advertised jobs, but they also exfiltrated keys for AI providers such as OpenAI, DeepSeek, and SiliconFlow. The real exposure is the AI account behind the plugin, not just the IDE. Stolen keys can be reused for model access, billing abuse, and any data or prompts those accounts can reach, and the same marketplace can also be used to hand out keys to paying users, which complicates cleanup and attribution.

Part of the PlainSec briefing for 2026-06-18

Sources