Fifteen malicious JetBrains plugins steal AI keys from developers
Researchers at Aikido have identified 15 malicious plugins on the JetBrains Marketplace targeting users of the company's developer tools. The plugins carry different names but contain similar code that exfiltrates stored AI provider API keys to an external server. They are variants of development helper tools with names such as "DeepSeek Code Review" and "AI Git Commitor". The plugins work as advertised, but also transmit the user's API key the moment it is entered and the user clicks "Apply". The campaign dates back to late October 2025, with new plugins still appearing in June 2026.
What this means for your organisation
API keys for AI services are tied to your company account and your invoice. Stolen keys are used to run someone else's workload at your expense, and they can expose data sent through the service. Developer tooling is normally installed by developers themselves without approval, which makes this a purchase nobody had visibility into. That the campaign ran for more than half a year without being stopped says something about how little vetting plugin marketplaces apply.
Berigo recommends
- Review which IDE plugins your developers have installed and remove anything unapproved.
- Rotate every AI service API key that has been entered into a development tool.
- Set spending limits and alerts on your AI accounts so abuse surfaces in hours, not on the invoice.
- Establish an approved list of development tool plugins, on the same footing as other software management.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch