Affected Systems
JetBrains Marketplace users who installed any of the 15+ malicious plugins. Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.) with AI API keys configured. Specific plugin names and versions not provided in summary.
Exploitation Status
Active supply chain attack. Malicious plugins were live on the official JetBrains Marketplace and actively stealing credentials from developers who installed them. Plugins have been discovered but removal status unclear.
Business Impact
Stolen AI API keys (OpenAI, Anthropic, etc.) can lead to unauthorized usage charges, data exfiltration through prompt injection, and potential exposure of proprietary code or data sent to AI services. Organizations may face unexpected cloud bills and compliance issues if API keys are abused. Developer workstations are compromised supply chain entry points.
Urgency
🟠Within 24 hours
Recommended Actions
- Audit all installed JetBrains IDE plugins immediately and remove any unrecognized or suspicious extensions from developer workstations
- Rotate all AI service API keys (OpenAI, Anthropic, Google AI, Azure OpenAI, etc.) used by development teams as a precaution
- Review API usage logs and billing for anomalous activity indicating unauthorized key usage
- Implement centralized plugin approval process requiring security review before developers install JetBrains Marketplace plugins
- Monitor JetBrains security advisories for the list of confirmed malicious plugin names and compare against your environment
