VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_1d5a81ae1b09677ec4e01519814dc48a

Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

Published Jun 17, 2026

Cybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys.

"Every plugin poses as an AI coding assistant built on DeepSeek and other large language models, offering chat, commit messages, code review, bug finding, and unit tests,"

Affected AI Products

large language model deepseek
Get the weekly digest. Every Monday: top AI security stories of the week. Free.