15 Malicious JetBrains Plugins Caught Stealing DeepSeek, OpenAI API Keys

https://hackread.com/wp-content/uploads/2026/06/malicious-jetbrains-plugins-caught-stealing-deepseek-openai-api-keys-1024x576.png

Cybercriminals are using fake artificial intelligence (AI) tools to target software developers in a coordinated supply chain attack on the JetBrains Marketplace. The compromise was first discovered by the Code security firm Aikido Security, which found 15 published plugins designed as AI coding assistants built on large language models (LLMs) like DeepSeek.

The first fake plugins came out at the end of October 2025, and new ones dropped as recently as June 2026. Scammers used seven different seller accounts to publish them. Collectively, people downloaded these malicious plugins nearly 70,000 times. Some of the most downloaded plugins are called CodeGPT AI Assistant and DeepSeek AI Assist. The hackers also added fake five-star reviews to make the tools look safe.

Like similar campaigns, this one’s modus operandi includes installing extensions and exfiltrating the user’s private AI authentication credentials to a static, hard-coded server controlled by attackers.

The Infiltration Method

...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more

https://cdn.theatlantic.com/thumbor/XRcDfEUMuAcwYSWnXS3dxsMld7A=/0x43:2000x1085/1200x625/media/img/mt/2026/10/2026_10_02_Robinsons_open_ai_safety_final/original.jpg

David Robinson, ex-OpenAI safety and policy: SV lacks a safety-centric culture; labs must study other fields' safety approaches; time for trial and error's over

Sponsor Posts Subquadratic: the LLM built for 12M-token reasoning — SubQ can reason across entire codebases and document sets in one pass with no RAG workarounds. Read how SubQ 1.1 Small holds near-perfect retrieval out to 12M tokens. Introducing Campus: The digital home for educational institutions — Every educational institution needs