Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

Cybersecurity researchers have flagged a “coordinated malware campaign” on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys.

“Every plugin poses as an AI coding assistant built on DeepSeek and other large language models, offering chat, commit messages, code review, bug finding, and unit tests,”

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor An advanced malware previously attributed to a China-linked threat actor has resurfaced after more than four years within a Taiwan manufacturing

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client

Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and

Google replaced Git tags for certain source code with obtaining via Google Drive

Google replaced Git tags for certain source code with obtaining via Google Drive Source: Hacker News