Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
JetBrains IDE Plugins Compromise 70,000+ API Keys

JetBrains IDE Plugins Compromise 70,000+ API Keys

Posted on June 17, 2026 By CWS

In a significant security breach, over 70,000 API keys have been compromised due to malicious plugins on the JetBrains Marketplace. These harmful plugins, masquerading as legitimate AI-enhanced coding tools, have been downloaded extensively, primarily by developers seeking advanced features.

Malicious Plugins Disguised as AI Tools

Research by Aikido revealed that the compromised plugins were distributed through seven vendor accounts, falsely presenting themselves as helpful AI-powered developer assistants. They offered functionalities such as AI chat, code generation, and bug detection, appearing genuine while secretly extracting sensitive API keys.

These plugins, although functional, concealed their true intent. They captured users’ API keys for services like OpenAI and DeepSeek, operating covertly behind a facade of helpfulness. This stealthy approach allowed the malware to proliferate undetected.

Technical Insights into the Breach

Each identified plugin shared a similar codebase, slightly modified to evade detection. Upon entering API keys, developers unknowingly triggered the theft mechanism. The captured keys were sent to a command-and-control server through unencrypted HTTP requests, exposing them to further interception risks.

The plugins even offered a paid tier, complicating the threat landscape. Post-payment, users received new API keys controlled by attackers, suggesting a possible resale operation of stolen credentials. This dual strategy enabled attackers to profit from both stolen keys and subscription fees.

Implications and Recommended Actions

Active since October 2025, the campaign continues to evolve, with new malicious plugins emerging as recently as June 2026. The true scope remains uncertain due to potential manipulation of download statistics and fake positive reviews.

The incident underscores the vulnerability of Integrated Development Environments (IDEs) to supply chain attacks. These environments harbor critical information like source code and API keys, making them lucrative targets. Despite JetBrains’ security measures, hidden malicious functions can escape detection.

Future Outlook and Security Recommendations

Developers are urged to uninstall affected plugins and revoke compromised API keys immediately. Regular credential rotation and monitoring for unusual API activity are crucial. Experts advise treating IDE plugins as high-risk components and only engaging with trusted sources.

In response to this growing threat, organizations should adopt endpoint monitoring solutions and enhance software supply chain security protocols. This breach highlights the escalating risk of developer-targeted attacks and the necessity for increased vigilance when incorporating third-party tools into development workflows.

Cyber Security News Tags:Aikido, API keys, API theft, Cybersecurity, developer tools, Development, endpoint monitoring, IDE, JetBrains, Malware, PlugIns, Security, Software Security, supply chain attack, vigilance

Post navigation

Previous Post: 1Password Buys Apono to Enhance Access Management
Next Post: Discover How Modern Threats Bypass MFA in Our Webinar

Related Posts

Kali Linux 2025.4 Released With 3 New Hacking Tools and Wifipumpkin3 Kali Linux 2025.4 Released With 3 New Hacking Tools and Wifipumpkin3 Cyber Security News
SoundCloud Confirms Data Breach Following VPN and Access Issues SoundCloud Confirms Data Breach Following VPN and Access Issues Cyber Security News
Cisco Acquires Astrix to Bolster AI Identity Security Cisco Acquires Astrix to Bolster AI Identity Security Cyber Security News
Real-Time Threat Intelligence for Proactive Cyber Defense in 2025 Real-Time Threat Intelligence for Proactive Cyber Defense in 2025 Cyber Security News
CISA Warns of WHILL Model C2 Wheelchairs Vulnerability Let Attackers Take Control of Product CISA Warns of WHILL Model C2 Wheelchairs Vulnerability Let Attackers Take Control of Product Cyber Security News
Multi-Stage Windows Malware Invokes PowerShell Downloader Using Text-based Payloads Using Remote Host Multi-Stage Windows Malware Invokes PowerShell Downloader Using Text-based Payloads Using Remote Host Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Tenet Security Launches with $6M Seed Funding for AI Defense
  • Critical Oracle PeopleSoft Vulnerability Exploited in Attacks
  • Discover How Modern Threats Bypass MFA in Our Webinar
  • JetBrains IDE Plugins Compromise 70,000+ API Keys
  • 1Password Buys Apono to Enhance Access Management

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Tenet Security Launches with $6M Seed Funding for AI Defense
  • Critical Oracle PeopleSoft Vulnerability Exploited in Attacks
  • Discover How Modern Threats Bypass MFA in Our Webinar
  • JetBrains IDE Plugins Compromise 70,000+ API Keys
  • 1Password Buys Apono to Enhance Access Management

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark