JetBrains Marketplace AI Key Theft — 15 Malicious Plugins, 70K Installs, TLS Bypass

Security breakdown of 15 malicious JetBrains IDE plugins stealing OpenAI, Anthropic, and AWS API keys from 70,000 developers.

JetBrains Marketplace AI Key Theft — 15 Malicious Plugins, 70K Installs, TLS Bypass
📌
Security Roundup Series: Week of June 18, 2026 • 4 min read deep dive

This post is part of the Week of June 19, 2026 Security Roundup.

Overview

A coordinated malware campaign targeting developer tooling was discovered on June 16, 2026: 15 malicious plugins hosted on JetBrains Marketplace were found to silently exfiltrate AI provider API keys — including keys for OpenAI, Anthropic (Claude), DeepSeek, Mistral, and Cohere — to a hardcoded command-and-control server. Combined install count across affected plugins: approximately 70,000. The campaign ran from October 2025 through June 10, 2026.

How the Attack Worked

Each plugin presented itself as a legitimate AI productivity utility for IntelliJ IDEA, PyCharm, GoLand, and other JetBrains IDEs. The exfiltration mechanism was triggered the moment a developer entered their AI provider API key into the plugin's settings dialog and clicked Apply:

  1. TLS bypass: The plugin registered a JVM-wide X509TrustManager that disabled standard TLS certificate validation, preventing network monitoring tools, local MITM proxies, and IDE debuggers from flagging the outbound connection.
  2. Plaintext exfiltration: The validated API key was serialized as a plaintext JSON payload and sent via unencrypted HTTP to the hardcoded C2 IP 39.107.60[.]51.
  3. Stealth: The exfiltration call was made in a background thread to avoid blocking the UI, with no visible indication to the developer that anything had occurred.

Timeline

  • October 2025: First malicious plugins published under 7 publisher accounts
  • October 2025 – June 2026: Ongoing publication of new plugin versions; combined install count grows to ~70,000
  • June 10, 2026: Most recent malicious version published
  • June 16, 2026: Campaign discovered and disclosed; all 15 plugins removed, 7 publisher accounts permanently terminated

Affected Plugin Names

JetBrains has not published the complete list, but affected plugins were described as AI assistant, AI code completion, AI chat, and AI review utilities. If you installed any AI-related plugin from JetBrains Marketplace between October 2025 and June 10, 2026, treat your AI provider keys as compromised.

Impact Assessment

Stolen AI API keys enable attackers to:

  • Run up substantial LLM inference charges on the victim's billing account
  • Access any fine-tuned models, files, or assistants associated with the API key
  • Use the victim's key as infrastructure for further attacks (phishing generation, malware obfuscation)
  • In the case of Anthropic Keys with Claude API access: query Claude on behalf of the victim, potentially exposing proprietary prompts and business logic

Remediation

  • Immediately rotate all AI provider API keys on any developer machine that had a JetBrains AI plugin installed between October 2025 and June 16, 2026.
  • Audit your IDE plugins: Settings → Plugins → Installed — remove any AI plugins not verified as safe. Check the JetBrains Security Advisory for the confirmed list of removed plugins.
  • Review billing dashboards at OpenAI, Anthropic, DeepSeek, and other providers for unexpected usage spikes.
  • Going forward: Restrict outbound network access from IDE processes using endpoint firewall rules; consider blocking JVM-level TLS bypass attempts via security agents.

IOCs

  • C2 IP: 39.107.60[.]51
  • Behavior: JVM-wide X509TrustManager registration that disables certificate validation at plugin load time
  • Network indicator: Plaintext HTTP POST to 39.107.60[.]51 containing JSON with an API key-shaped string immediately following plugin settings save

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther