Înapoi la știri

Malicious JetBrains Marketplace plugins steal AI API keys from developers - BleepingComputer

2 ore în urmă
5 minute min
Andrei Miroslavescu
At least 15 malicious plugins found on the JetBrains Marketplace were designed to steal AI API keys from developers. The campaign, discovered by Aikido Security, includes plugins that act as AI coding assistants, code-review tools, and Git utilities powered by popular AI services such as OpenAI, DeepSeek, and SiliconFlow. "We detected a coordinated malware campaign on the JetBrains Marketplace," warns Aikido. "At least 15 IDE plugins, published under seven vendor accounts, share the same hidden behavior. Each one exfiltrates the AI provider API key that you stored into its settings, and together they have been installed close to 70,000 times." According to Aikido, the malicious plugins were first published in October 2025, with new plugins continuing to be published as recently as June 10, 2026. The researchers say the plugins function as advertised, but secretly transmit AI API keys entered by users into the plugin settings back to the attackers. According to the report, the theft occurs when a user clicks "Apply" after entering an API key, causing the credential to be sent to a hardcoded server at 39.107.6051 over HTTP at this URL: hxxp://39.107.6051/api/software/key The researchers found that all 15 plugins share similar code that were submitted as different Marketplace plugins.  Aikido also discovered functionality that allows the remote server to provide AI API keys to paid users. While it is unclear where these API keys are coming from, Aikido theorizes that the plugin operators may be harvesting credentials from the free users and then providing them to the paid users. "The plugins also run a paid tier. After a user pays a small fee through the donation wall built into the plugin, the server sends an API key back
Publicitate
down to the client, and the plugin starts using that key for its model calls instead of your own, which is bizarre, since no legitimate operator would simply hand a user a working and unrestricted key to a paid AI provider," says Aikido. BleepingComputer downloaded and analyzed the latest version of the DeepSeek AI Assist plugin (plugin ID: ord.cp.code.ai.kit) and independently confirmed that it still contains the credential theft code described in Aikido's report. At the time of writing, the plugin remained available for download through the JetBrains Marketplace. The campaign plugins discovered by Aikido are: The two most downloaded plugins are DeepSeek AI Assist (27,727 downloads) and CodeGPT AI Assistant (25,571 downloads). However, the researchers warn that download counts can be manipulated and should not necessarily be treated as unique installations. While malicious packages are commonly discovered on repositories such as npm and PyPI, reports of credential-stealing plugins distributed through the JetBrains Marketplace are far less common. BleepingComputer contacted JetBrains about the malicious plugins, but has not received a response as of publication. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Vibe coders are gonna vibe code: How CISOs are tackling code sprawl Why AI-driven threats are exposing the limits of MSP security stacks XBOW tests Anthropic's Mythos Preview for offensive security Why the browser is now the front line for AI security How Varonis Atlas integrates Claude Compliance API for AI governance
Alte postari din Tech
Tech

Honor’s Magic V6 sets three foldable firsts - The Verge

On paper, the Honor Magic V6 sounds like a tremendous leap forward for foldable phones: It’s the thinnest one yet, with the biggest battery, and the best water-resistance ever. In practice, only the bigger battery feels like a meaningful improvement.

Tech

Apple still has three unannounced iOS 27 features in the pipeline: report - 9to5Mac

Apple wrapped up its WWDC 2026 keynote this week, outlining all of its major new software features for the coming year, with Siri AI and improved stability taking the spotlight. That said, there are a few new features that are reportedly still in the works, and we should still see them by September, per Bloomberg’s Mark Gurman.

Tech

iOS 27 Adds Landscape Mode to More Apple Apps Ahead of 'iPhone Ultra' - MacRumors

iOS 27 enables landscape mode in more of Apple's built-in iPhone apps, including Apple Music, Podcasts, Fitness, Health, Reminders, Home, Shortcuts, Apple Watch, Find My, Weather, Voice Memos, Apple TV Remote, and others. In the Apple Music and Podcasts apps, landscape support is limited to the audio player for now.

Acasa Recente Radio Județe