Malicious JetBrains Plugins Steal AI Keys

Cybersecurity researchers have uncovered a large malware campaign targeting software developers. The campaign uses fake AI coding tools to steal valuable AI service keys. These plugins appear helpful at first glance. However, they secretly send user credentials to attacker-controlled servers. As a result, developers may lose access to paid AI services and face unexpected costs.

Fake AI Plugins Hide Credential Theft

Researchers found at least 15 malicious plugins in a popular developer marketplace. These tools claimed to offer AI-powered coding features. For example, they promised code reviews, bug detection, unit testing, and chat assistance. Therefore, many developers may have trusted them without suspicion. However, the plugins secretly collected API keys entered by users.

The malicious tools worked as advertised in many cases. As a result, users had little reason to suspect wrongdoing. However, hidden code sent AI provider credentials to a remote server. The transfer happened through unsecured requests. Therefore, attackers could easily capture and store the stolen information. Researchers believe the campaign started in late 2025 and continued into 2026.

Attackers Profit From Stolen AI Credentials

Some of the malicious plugins gained significant attention. In fact, several tools reportedly received tens of thousands of downloads. However, researchers could not verify those numbers. Therefore, attackers may have inflated the counts to appear trustworthy. This tactic often helps malicious software spread faster.

Researchers also discovered a strange payment system. Users could pay a small fee through the plugin interface. After payment, the server returned a working AI key. Therefore, users could access premium AI services without using their own credentials. However, researchers believe these keys likely came from previous victims. As a result, legitimate account owners may unknowingly pay for another user’s activity.

This model creates profits from both sides of the operation. Attackers collect payments from customers. Meanwhile, they harvest credentials from unsuspecting victims. Therefore, the campaign may function as an illegal credential-sharing service. Researchers warn that this approach could attract more cybercriminal groups.

Developer Environments Face Growing Risks

The campaign highlights a growing threat to developer ecosystems. Today, development tools often store valuable credentials. For example, they may contain cloud access tokens, signing keys, and AI service credentials. Therefore, attackers increasingly target these environments.

Open-source platforms and plugin marketplaces offer convenience. However, they can also introduce security risks. A single malicious dependency may expose sensitive information. Therefore, experts urge developers to carefully review software before installation. In addition, they recommend avoiding the use of long-term credentials in unverified tools.

Malicious Browser Extensions Capture AI Chats

Researchers also uncovered another threat involving browser extensions. These extensions claimed to block advertisements for users. However, hidden functions monitored conversations with AI chatbots. As a result, sensitive discussions could be collected without clear user awareness.

The extensions reportedly gathered information from several major AI platforms. For example, they captured chat histories, model usage details, and subscription information. Therefore, attackers could gain valuable insights into user behavior. Researchers named this activity “PromptSnatcher.”

Both extensions remained available for years before researchers exposed them. Therefore, experts suspect the spying features arrived through later updates. This approach allowed the tools to build trust before collecting data. However, users likely had little indication that monitoring was taking place.

Prompt Poaching Becomes a Growing Concern

This activity belongs to a technique known as prompt poaching. In this attack, software secretly collects AI conversations. The stolen data may include private business discussions, research, and personal information. Therefore, prompt poaching presents serious privacy risks.

Some extensions claim they collect data for security improvements. However, researchers found evidence of undisclosed data transmission. As a result, users may not fully understand how their information is handled. Furthermore, questions remain about compliance with browser extension policies.

How to Prevent AI Credential and Chat Theft

Organizations should carefully review every plugin and browser extension before installation. In addition, teams should monitor software behavior and network activity for unusual connections. Therefore, suspicious tools can be identified before major damage occurs. Companies should also use privileged access management to limit exposure of sensitive credentials.

Furthermore, continuous security monitoring and threat detection services can quickly identify unauthorized data transfers and reduce the risk of credential theft.

Sleep well, we got you covered.

Scroll to Top