Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

Cybersecurity researchers have flagged a “coordinated malware campaign” on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys.

“Every plugin poses as an AI coding assistant built on DeepSeek and other large language models, offering chat, commit messages, code review, bug finding, and unit tests,”

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze

METR and Redwood Offer Holy %^ Postmortem of the HuggingFace Hack

METR and Redwood Offer Holy %^ Postmortem of the HuggingFace Hack Source: Hacker News

Qwen-Image-3.0: Rich Content, Authentic Details, Deep Knowledge

Qwen-Image-3.0: Rich Content, Authentic Details, Deep Knowledge Source: Hacker News