Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› JetBrains Marketplace AI Plugin Campaign 2026: How 15…
Breach analysis Incident: 16 Jun 2026

JetBrains Marketplace AI Plugin Campaign 2026: How 15 Fake AI Coding Assistants Stole Developers’ AI API Keys

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 12 min read
Attack route: Supply chain Identities: API key
On this page

From late October 2025 to June 2026, an attacker published at least 15 AI coding assistant plugins on the JetBrains Marketplace that quietly stole the AI provider API keys developers typed into them. Aikido Security disclosed the campaign on 16 June 2026 and counted about 70,000 installations across the plugins, which were published under seven vendor accounts. The plugins worked as advertised, offering chat, commit messages, code review and unit tests, but the moment a user saved an OpenAI, DeepSeek or SiliconFlow key, it was sent in plaintext over HTTP to a server at 39.107.60.51. Researchers also found a paid tier that appears to have handed stolen keys back to paying users. JetBrains removed the plugins, banned the publisher accounts and remotely disabled the extensions in users' IDEs. The campaign is a clear example of how AI provider API keys, which are non-human identities with direct billing and data access, can be harvested at the point where a developer configures a tool.

Key takeaways

  • Aikido Security identified 15 malicious plugins across seven vendor accounts, with the earliest dated 31 October 2025 and the latest version on 10 June 2026. It reported about 70,000 total installations; that is a download count, not a verified number of individual developers.
  • The entry point was trust in a curated marketplace: developers installed apparently useful AI assistants and pasted in their own API keys, which the plugin code forwarded to the attacker when the settings were applied.
  • The identities abused were AI provider API keys for OpenAI, DeepSeek and SiliconFlow. StepSecurity found the code checked for the OpenAI key format before exfiltrating it.
  • JetBrains received reports on 16 June 2026, removed all 15 plugins, permanently terminated seven publisher accounts and marked the plugins as broken so they are disabled on the next IDE restart.
  • Lesson: any tool that asks for an API key becomes a custodian of that identity. Use scoped keys with spending caps, keep an inventory of where each key has been entered, and rotate quickly when a tool turns out to be malicious.

At a glance

Organisation(s)JetBrains Marketplace (platform); developers who installed the plugins; AI providers whose keys were targeted (OpenAI, DeepSeek, SiliconFlow)
WhenFirst plugin dated 31 October 2025; latest version 10 June 2026; disclosed by Aikido Security on 16 June 2026
AttackerUnattributed operator behind seven publisher accounts (CodePilot, StackSmith, CodeCrafter, CodeWeaver, JetCode, DailyCode, ZenCoder); StepSecurity says the collection server was hosted on Alibaba Cloud in Beijing
Entry pointMalicious but functional AI assistant plugins listed on the JetBrains Marketplace
Identities abusedAI provider API keys entered by developers into plugin settings
ImpactAbout 70,000 installations across 15 plugins according to Aikido Security and StepSecurity; the number of keys actually stolen has not been published
CategoryNHI (API keys), LLM / AI platform, software supply chain

What happened

On 16 June 2026, Aikido Security researcher Ilyas Makari published details of a coordinated campaign on the JetBrains Marketplace, the official plugin store for JetBrains IDEs. Aikido found that "At least 15 IDE plugins, published under seven vendor accounts, share the same hidden behavior", as quoted by BleepingComputer. Each plugin presented itself as an AI helper for coding tasks, with names such as DeepSeek AI Assist, CodeGPT AI Assistant, DeepSeek Git Commit, DeepSeek FindBugs and DeepSeek Junit Test.

The plugins were not empty shells. Makari wrote that "They function exactly as advertised", as quoted by The Hacker News, providing chat, commit messages, code review, bug finding and unit test generation through the user's own AI provider account. To use them, a developer had to paste an API key into the plugin settings. According to Aikido, "The moment you click Apply, the settings handler stores your key and also forwards it to the attacker". There was no prompt or confirmation screen.

The key was sent as a plaintext JSON payload over unencrypted HTTP to a hard-coded server at 39.107.60.51, using a static token to authenticate to the attacker's API. StepSecurity, which published its own analysis on 18 June, reported that the validation logic checked for the sk- prefix and a 51-character length matching the OpenAI key format. It also found that the plugins installed a JVM-wide X509TrustManager that disabled standard TLS certificate validation.

Aikido and StepSecurity both describe a second source of revenue. Plugins offered a paid tier behind a donation wall, and when a user paid, the server returned a working API key. StepSecurity said this key was "likely one stolen from another victim", creating what it called "a self-sustaining fraud cycle". Aikido also suggested the operator was reselling stolen credentials to paying users.

The download counts published by Aikido show how the campaign grew. Twelve plugins released between October 2025 and April 2026 had between 278 and 3,498 downloads each. Two plugins dated 9 and 10 June 2026, CodeGPT AI Assistant and DeepSeek AI Assist, accounted for 25,571 and 27,727 downloads respectively, well over half of the roughly 70,000 total. BleepingComputer reported on 16 June that JetBrains had not responded and that the plugins were still available when it published.

JetBrains published a security update on its Platform blog, updated on 18 June 2026. It said that on 16 June it "received reports about 15 third-party plugins", removed them from the Marketplace, permanently terminated seven publisher accounts and flagged the plugins in its backend. It stated: "All affected plugins have been explicitly marked as broken within our backend architecture." It also said its security team found no access to JetBrains source code, development environments or corporate infrastructure. StepSecurity reported that the attacker's server was still live and responding to API requests on 19 June.

Timeline

DateEvent
31 October 2025DeepSeek Junit Test, the earliest plugin in Aikido's list, is published.
November 2025 to February 2026Ten more plugins are released under several vendor accounts, according to Aikido's table.
18 April 2026DeepSeek Code Review is published.
9 to 10 June 2026CodeGPT AI Assistant and DeepSeek AI Assist are dated; together they reach more than 53,000 downloads.
16 June 2026Aikido Security discloses the campaign; BleepingComputer reports the plugins are still listed. JetBrains receives reports about the 15 plugins.
17 June 2026The Hacker News and StepSecurity report that JetBrains has removed all 15 plugins, blocked the seven publisher accounts and disabled the plugins remotely.
18 June 2026JetBrains updates its security post; StepSecurity publishes its analysis of the exfiltration infrastructure.
19 June 2026StepSecurity confirms the attacker's server is still live and answering API requests.

How it happened: the identity attack path

  1. Publisher identities created. The operator set up seven vendor accounts on the JetBrains Marketplace and spread 15 plugins across them, so that no single account looked like a large operation. Aikido says all 15 share renamed and repackaged versions of the same code.
  2. Marketplace review passed. Aikido notes that JetBrains plugins go through a manual review before approval, yet the campaign "slipped through". JetBrains later said its Plugin Verifier "was architected as a compatibility and API-usage checker rather than a dedicated data-flow or anti-malware scanner."
  3. Developer trust borrowed. Plugin names used popular AI brands such as DeepSeek and CodeGPT, and the tools worked as described, so users had no functional reason to suspect them.
  4. Credentials requested as normal configuration. Bring-your-own-key is a common pattern for AI tools, so asking the user to paste an API key into settings looked routine.
  5. Key exfiltrated on save. When the user clicked Apply, the settings handler stored the key locally and sent it over plain HTTP to 39.107.60.51, after checking it matched the expected key format.
  6. Stolen keys monetised. According to Aikido and StepSecurity, the server could return a working key to users who paid through the plugin's donation wall, and victims' keys could also be used directly against their provider accounts.

Impact

Aikido Security, StepSecurity, BleepingComputer and Infosecurity Magazine all cite about 70,000 installations across the 15 plugins. The per-plugin figures in Aikido's and StepSecurity's tables add up to just under 70,000. These are marketplace download counts. They do not tell us how many distinct developers installed a plugin, and they do not tell us how many users entered a key. The old framing of "70,000 developers" is therefore not supported by the sources; "about 70,000 installations" is the accurate figure.

No source has published the number of API keys received by the attacker's server or the financial losses on victims' AI provider accounts. The potential impact for each affected developer is unauthorised use of their AI account: charges for model usage, exhaustion of quotas, and, depending on the provider and key scope, access to data and resources associated with that account. JetBrains and StepSecurity both advise treating any key entered into these plugins as compromised.

JetBrains says its own infrastructure was not affected.

What this means for NHI governance

The campaign did not exploit a vulnerability. It exploited the ordinary way developers connect tools to AI services: generate a long-lived API key, paste it into a plugin, and forget about it. Each of those keys is a non-human identity with its own permissions and its own bill attached. Once it is entered into a third-party tool, that tool becomes a custodian of the identity, and the organisation usually has no record that the key was ever shared.

Three governance gaps stand out. First, most AI provider keys are created by individuals, often on personal or team accounts, with broad scope and no spending cap, so a stolen key is immediately useful to an attacker. Second, there is rarely an inventory linking a key to the tools it has been entered into, which makes it hard to know what to rotate when a tool is found to be malicious. Third, marketplace review is not a security boundary. JetBrains was open that its verifier checked compatibility rather than data flows, and the same pattern has been seen in other developer ecosystems, including the GlassWorm VS Code extension campaign.

The donation-wall scheme described by researchers also matters. It suggests stolen AI keys have a direct resale value, which fits the wider pattern of attackers hijacking AI accounts with compromised credentials, as seen in the AI LLM hijack breach. As AI coding tools spread through engineering teams, their credentials need the same controls as cloud keys and CI secrets.

Recommendations

  • Remove the plugins and revoke the keys. Uninstall any of the 15 plugins, even though JetBrains has disabled them, and revoke every API key that was entered into them. Generate new keys rather than reusing old ones.
  • Check provider usage. Review OpenAI, DeepSeek and SiliconFlow account logs and billing for unfamiliar usage since the key was entered, and block 39.107.60.51 at the network edge as JetBrains and StepSecurity advise.
  • Scope keys and cap spending. Issue a separate, narrowly scoped key per tool, with spending limits on the provider account, so a single stolen key has a small blast radius. The LLM Provider API Key Security and LLMjacking Guide covers these controls in detail.
  • Record where every key lives. Keep an inventory of AI provider keys, their owners and the tools they have been entered into, and retire them on a schedule, following the API Key Management Guide.
  • Control IDE plugins. Maintain an allow list of approved plugins and publishers for development machines, and treat new AI assistants from unknown vendors with the same care as new dependencies. The AI Coding Agents Security Guide sets out wider controls for AI tools in the development environment.
  • Monitor developer egress. Alert on plaintext HTTP connections from IDE processes and on tools that change JVM trust settings, both of which were signals in this campaign.

Frequently asked questions

What happened in the JetBrains Marketplace AI plugin campaign?

Between October 2025 and June 2026, at least 15 plugins posing as AI coding assistants were published on the JetBrains Marketplace. They worked as advertised but sent any OpenAI, DeepSeek or SiliconFlow API key a user saved in their settings to an attacker-controlled server. Aikido Security disclosed the campaign on 16 June 2026.

Did 70,000 developers have their API keys stolen?

Not as far as the sources show. Aikido Security and StepSecurity report about 70,000 installations across the 15 plugins. That is a download total, not a count of distinct developers, and only users who entered a key into a plugin would have had it stolen. No source has published how many keys the attacker collected.

Was JetBrains itself breached?

No. JetBrains says no internal source code, development environments or corporate infrastructure were accessed. The attacker used ordinary publisher accounts to list the plugins. JetBrains removed them, terminated seven accounts and remotely disabled the plugins in users' IDEs on the next restart.

GlassWorm VS Code extension campaign · Hard-coded secrets in VS Code extensions · AI LLM hijack breach · Secrets Management Guide · NHI breaches

How NHI Mgmt Group can help

AI provider API keys are now one of the most sought-after non-human identities, and they often sit outside any central inventory or rotation process. Our NHI Foundation Level Training Course helps teams find, scope and govern these keys alongside the rest of their machine identities.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org