Cybersecurity researchers have identified 15 malicious plugins on the JetBrains Marketplace that steal AI provider API keys, alongside two Chrome extensions caught exfiltrating private user conversations with chatbots.
Key Points
- Aikido Security discovered 15 malicious JetBrains plugins masquerading as AI coding assistants that exfiltrate user API keys to a remote server.
- Popular plugins like CodeGPT AI Assistant and DeepSeek AI Assist have recorded over 25,000 downloads each since the campaign began in October 2025.
- Attackers monetize the stolen credentials by selling access to victim API keys while simultaneously charging users for a fake "paid tier" service.
- Two Chrome extensions, Smart Adblocker and Adblock for Browser, were found capturing private chat data from platforms including ChatGPT, Claude, and Gemini.
- The Chrome extensions use a custom interception engine to siphon conversation history and account metadata under the guise of legitimate ad-blocking functionality.