Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
JetBrains IDE Plugins Compromise 70,000+ API Keys

JetBrains IDE Plugins Compromise 70,000+ API Keys

Posted on June 17, 2026 By CWS

In a significant security breach, over 70,000 API keys have been compromised due to malicious plugins on the JetBrains Marketplace. These harmful plugins, masquerading as legitimate AI-enhanced coding tools, have been downloaded extensively, primarily by developers seeking advanced features.

Malicious Plugins Disguised as AI Tools

Research by Aikido revealed that the compromised plugins were distributed through seven vendor accounts, falsely presenting themselves as helpful AI-powered developer assistants. They offered functionalities such as AI chat, code generation, and bug detection, appearing genuine while secretly extracting sensitive API keys.

These plugins, although functional, concealed their true intent. They captured users’ API keys for services like OpenAI and DeepSeek, operating covertly behind a facade of helpfulness. This stealthy approach allowed the malware to proliferate undetected.

Technical Insights into the Breach

Each identified plugin shared a similar codebase, slightly modified to evade detection. Upon entering API keys, developers unknowingly triggered the theft mechanism. The captured keys were sent to a command-and-control server through unencrypted HTTP requests, exposing them to further interception risks.

The plugins even offered a paid tier, complicating the threat landscape. Post-payment, users received new API keys controlled by attackers, suggesting a possible resale operation of stolen credentials. This dual strategy enabled attackers to profit from both stolen keys and subscription fees.

Implications and Recommended Actions

Active since October 2025, the campaign continues to evolve, with new malicious plugins emerging as recently as June 2026. The true scope remains uncertain due to potential manipulation of download statistics and fake positive reviews.

The incident underscores the vulnerability of Integrated Development Environments (IDEs) to supply chain attacks. These environments harbor critical information like source code and API keys, making them lucrative targets. Despite JetBrains’ security measures, hidden malicious functions can escape detection.

Future Outlook and Security Recommendations

Developers are urged to uninstall affected plugins and revoke compromised API keys immediately. Regular credential rotation and monitoring for unusual API activity are crucial. Experts advise treating IDE plugins as high-risk components and only engaging with trusted sources.

In response to this growing threat, organizations should adopt endpoint monitoring solutions and enhance software supply chain security protocols. This breach highlights the escalating risk of developer-targeted attacks and the necessity for increased vigilance when incorporating third-party tools into development workflows.

Cyber Security News Tags:Aikido, API keys, API theft, Cybersecurity, developer tools, Development, endpoint monitoring, IDE, JetBrains, Malware, PlugIns, Security, Software Security, supply chain attack, vigilance

Post navigation

Previous Post: 1Password Buys Apono to Enhance Access Management
Next Post: Discover How Modern Threats Bypass MFA in Our Webinar

Related Posts

Millenium RAT Malware Threat Grows, Infections Skyrocket Millenium RAT Malware Threat Grows, Infections Skyrocket Cyber Security News
New DPRK Interview Campaign Leverages Fake Fonts to Deploy Malware New DPRK Interview Campaign Leverages Fake Fonts to Deploy Malware Cyber Security News
Crimson Collective Claims to have Disconnected Many Brightspeed Home Internet Users Crimson Collective Claims to have Disconnected Many Brightspeed Home Internet Users Cyber Security News
Kibana Crowdstrike Connector Vulnerability Exposes Protected Credentials Kibana Crowdstrike Connector Vulnerability Exposes Protected Credentials Cyber Security News
Gootloader with Low Detection Rate Bypasses Most Security Tools Gootloader with Low Detection Rate Bypasses Most Security Tools Cyber Security News
Google Chrome 0-Day Vulnerability Exploited in the Wild to Execute Arbitrary Code Google Chrome 0-Day Vulnerability Exploited in the Wild to Execute Arbitrary Code Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark