Fake Developer Tools Caught Stealing AI Access Keys on Trusted Platform
At least 15 malicious plugins on JetBrains Marketplace stole AI service credentials from developers, showing how supply chain attacks now target everyday work tools.
Source
GetCyberRight Intelligence
Original headline: Malicious JetBrains Plugins Steal AI API Keys
Plain-English summary by GetCyberRight. Read the full report at the source above.
What Happened
Cybersecurity researchers discovered at least 15 malicious plugins on the official JetBrains Marketplace, a trusted platform where developers download tools for their work. These fake plugins were secretly stealing valuable AI API keys, including credentials for Claude, OpenAI, and other services. This attack matters because it happened on an official, vetted marketplace, not some sketchy website, showing that even legitimate platforms can host dangerous software.
The Details
JetBrains makes popular software development tools used by millions of professionals worldwide. Their marketplace is like an app store for developer productivity tools. The malicious plugins looked completely legitimate with professional descriptions and helpful-sounding features.
Once installed, these plugins quietly searched through developers' computers for API keys. These keys are like passwords that let you access AI services such as ChatGPT, Claude, and similar tools. When companies or individuals pay for these services, the keys unlock their accounts and credit balances. Stealing these keys means attackers can either use the services for free on someone else's account or sell the keys to others.
The plugins sat on the marketplace for an unknown period, harvesting credentials from unsuspecting users. This is called a supply chain attack because criminals poisoned a trusted source that people rely on daily. The attackers didn't need to hack individual computers. They simply waited for people to voluntarily install their malicious tools.
Who Is Affected
Software developers and programmers are the primary targets, especially those using AI coding assistants and tools. If someone in your household works in technology or software development, they may have been exposed. This also affects businesses that pay for AI services, since stolen keys can rack up unauthorized charges.
Anyone who uses JetBrains development tools (like IntelliJ IDEA, PyCharm, or WebStorm) should pay attention. Even if you're not a developer yourself, your employer's systems could be compromised if your work involves these tools. Students learning to code are also vulnerable if they installed plugins to help with coursework.
What You Should Do Right Now
Check installed plugins immediately. If you or someone in your household uses JetBrains tools, review all installed plugins and remove any that look unfamiliar or that you don't actively use.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
Rotate your AI service API keys. Log into OpenAI, Anthropic (Claude), and any other AI services you use. Generate new API keys and delete the old ones. This locks out anyone who may have stolen your credentials.
Review billing statements. Check your AI service accounts for unusual activity or unexpected charges from the past few months. Report any suspicious usage to the provider immediately.
Enable two-factor authentication. Add an extra security layer to your AI service accounts and any platforms where you store credentials.
Update from official sources only. Going forward, carefully review plugin developers, read recent reviews, and check installation counts before adding any tools to your software.
The Bigger Picture
This attack highlights how cybercriminals are evolving alongside technology. As AI tools become essential for work and learning, attackers target the credentials that unlock them. Supply chain attacks are particularly dangerous because they exploit our trust in established platforms. Staying informed about these threats helps you spot warning signs before installing software, even from sources you usually trust.
How GetCyberRight Can Help
Our Cyber Threat Radar tool tracks emerging supply chain attacks and credential theft trends affecting developers and AI tool users. It helps families understand which threats matter most to their specific situation. By monitoring these evolving risks, you can make informed decisions about the tools your household uses and protect valuable accounts before they're compromised.
Curated from trusted cybersecurity sources by GetCyberRight
Source: GetCyberRight IntelligenceStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

New Malware Steals Browser Passwords Without Leaving a Trace
Fileless malware is targeting passwords saved in your browser, making it invisible to traditional security software. Here's what families need to know.
3 min read
Invisible Malware Is Stealing Passwords Saved in Your Browser
A new type of malware steals passwords without leaving files on your computer, making it nearly impossible for antivirus software to detect.
3 min readHackers Hid Malware in Developer Tools to Steal Valuable AI Access Keys
15 malicious plugins in a popular developer marketplace stole AI API keys, leading to thousands in fraudulent charges. Here's what happened and how to protect yourself.
3 min read
Google AI Security Flaw Let Attackers Hijack Machine Learning Models
A vulnerability in Google's Vertex AI platform could have let attackers tamper with AI models. The flaw is now patched, but highlights growing risks in AI systems.
4 min read