Security firm Aikido Security has uncovered a coordinated malware campaign on the JetBrains Marketplace, where 15 malicious plugins disguised as AI coding assistants have been quietly harvesting developer API keys for OpenAI, DeepSeek, and SiliconFlow since October 2025. The plugins accumulated nearly 70,000 installations across seven vendor accounts, and the attackers weren’t just stealing credentials — they were reselling them to paying subscribers through a built-in donation mechanism. Your IDE just opened a subscription service for your own stolen property.
🤚 The Open-Palm Disclosure
The campaign is impressively brazen. Here’s how it works:
- A developer searches the JetBrains Marketplace for an AI coding assistant — a perfectly normal thing to do in 2026
- They install a plugin with a name like “DeepSeek AI Assist” (27,727 downloads) or “CodeGPT AI Assistant” (25,571 downloads), because the names sound exactly like things that should exist
- The plugin works. It genuinely provides AI coding assistance. This is the courtesy in the crime
- When the developer enters their API key and clicks “Apply,” the plugin transmits the credentials via unencrypted HTTP to an attacker-controlled server at 39.107.60[.]51
All 15 plugins share nearly identical malicious code, published across seven vendor accounts to create the illusion of a diverse marketplace rather than what it actually is: one person wearing seven hats, all of them stolen.
The full roster of malicious plugins reads like a DeepSeek fan fiction generator:
- DeepSeek Junit Test, DeepSeek Git Commit, DeepSeek FindBugs, DeepSeek AI Chat, DeepSeek Dev AI, DeepSeek AI Coding, DeepSeek Coder AI, DeepSeek Code Review, DeepSeek AI Assist
- AI FindBugs, AI Git Commitor, AI Coder Review, AI Coder Assistant
- CodeGPT AI Assistant, Coding Simple Tool
👐 The Two-Handed Subscription Model
The genuinely innovative part — and we use that word with the reluctance it deserves — is the monetization. These weren’t your standard credential harvesters that dump keys into a dark web paste. The attackers built a paid tier system.
Free users got their API keys stolen. Paying users — those who sent money through the plugin’s donation mechanism — received other people’s stolen API keys in return. The server would send a key back down to the client, and the plugin would start using that key instead of your own.
This is, in essence, a stolen credential marketplace disguised as a SaaS product. The attackers created a subscription service where the product is someone else’s bill. It’s Uber, but for your OpenAI invoice. It’s Netflix, but every movie was shoplifted from a different Blockbuster.
The keys were sent via unencrypted HTTP, which means the attackers couldn’t even be bothered with TLS. Your API credentials traveled across the internet in plaintext, like a postcard with your Social Security number written on it. In Comic Sans.
🌿 The Gentle Awakening
There is a quiet irony in developers — the very people who build security features, who review code for a living, who would never click a suspicious email attachment — installing plugins that steal their credentials because the plugin had “AI” in the name and a reasonable download count.
We have created an ecosystem where the phrase “AI-powered” functions as a trust badge. If it says AI, it must be legitimate. If it has 27,000 downloads, someone else must have vetted it. If it asks for your API key, well, how else would it work?
The JetBrains Marketplace, like npm, PyPI, the Chrome Web Store, and every other plugin ecosystem before it, operates on a model of assumed good faith that threat actors treat as a standing invitation. The campaign ran for eight months — from October 2025 to June 2026 — with new plugins being published as recently as June 10th. Eight months of “Apply” buttons routing credentials to an IP address in China.
👑 The Gold-Leaf Invoice
The broader implication is uncomfortable: AI API keys are now a high-value target, and the supply chain for AI tools is exactly as trustworthy as the supply chain for everything else, which is to say, not very.
Developers are storing API keys that can generate hundreds or thousands of dollars in compute charges, and they’re entering those keys into third-party plugins with the verification rigor of someone accepting a terms-of-service agreement. The attackers understood this perfectly. They didn’t need to exploit a zero-day or compromise a build pipeline. They just needed to publish a plugin that said “DeepSeek” in the name and wait.
If you’ve installed any AI coding plugin from the JetBrains Marketplace recently, now would be an excellent time to rotate your API keys, check your billing statements, and contemplate the philosophical implications of your productivity tools having a side hustle.
“The plugin stole your API key, resold it to a stranger, and charged you both for the privilege. If that’s not product-market fit, we don’t know what is.” — The Slap of Wisdom Developer Experience Team, rotating credentials from a text editor that doesn’t have an opinion