JetBrains Marketplace AI Key Theft — 15 Malicious Plugins, 70K Installs, TLS Bypass
Security breakdown of 15 malicious JetBrains IDE plugins stealing OpenAI, Anthropic, and AWS API keys from 70,000 developers.
This post is part of the Week of June 19, 2026 Security Roundup.
Overview
A coordinated malware campaign targeting developer tooling was discovered on June 16, 2026: 15 malicious plugins hosted on JetBrains Marketplace were found to silently exfiltrate AI provider API keys — including keys for OpenAI, Anthropic (Claude), DeepSeek, Mistral, and Cohere — to a hardcoded command-and-control server. Combined install count across affected plugins: approximately 70,000. The campaign ran from October 2025 through June 10, 2026.
How the Attack Worked
Each plugin presented itself as a legitimate AI productivity utility for IntelliJ IDEA, PyCharm, GoLand, and other JetBrains IDEs. The exfiltration mechanism was triggered the moment a developer entered their AI provider API key into the plugin's settings dialog and clicked Apply:
- TLS bypass: The plugin registered a JVM-wide
X509TrustManagerthat disabled standard TLS certificate validation, preventing network monitoring tools, local MITM proxies, and IDE debuggers from flagging the outbound connection. - Plaintext exfiltration: The validated API key was serialized as a plaintext JSON payload and sent via unencrypted HTTP to the hardcoded C2 IP
39.107.60[.]51. - Stealth: The exfiltration call was made in a background thread to avoid blocking the UI, with no visible indication to the developer that anything had occurred.
Timeline
- October 2025: First malicious plugins published under 7 publisher accounts
- October 2025 – June 2026: Ongoing publication of new plugin versions; combined install count grows to ~70,000
- June 10, 2026: Most recent malicious version published
- June 16, 2026: Campaign discovered and disclosed; all 15 plugins removed, 7 publisher accounts permanently terminated
Affected Plugin Names
JetBrains has not published the complete list, but affected plugins were described as AI assistant, AI code completion, AI chat, and AI review utilities. If you installed any AI-related plugin from JetBrains Marketplace between October 2025 and June 10, 2026, treat your AI provider keys as compromised.
Impact Assessment
Stolen AI API keys enable attackers to:
- Run up substantial LLM inference charges on the victim's billing account
- Access any fine-tuned models, files, or assistants associated with the API key
- Use the victim's key as infrastructure for further attacks (phishing generation, malware obfuscation)
- In the case of Anthropic Keys with Claude API access: query Claude on behalf of the victim, potentially exposing proprietary prompts and business logic
Remediation
- Immediately rotate all AI provider API keys on any developer machine that had a JetBrains AI plugin installed between October 2025 and June 16, 2026.
- Audit your IDE plugins:
Settings → Plugins → Installed— remove any AI plugins not verified as safe. Check the JetBrains Security Advisory for the confirmed list of removed plugins. - Review billing dashboards at OpenAI, Anthropic, DeepSeek, and other providers for unexpected usage spikes.
- Going forward: Restrict outbound network access from IDE processes using endpoint firewall rules; consider blocking JVM-level TLS bypass attempts via security agents.
IOCs
- C2 IP:
39.107.60[.]51 - Behavior: JVM-wide
X509TrustManagerregistration that disables certificate validation at plugin load time - Network indicator: Plaintext HTTP POST to
39.107.60[.]51containing JSON with an API key-shaped string immediately following plugin settings save