Affected Systems
JetBrains Marketplace users who installed any of 15+ malicious plugins impersonating AI coding assistants (DeepSeek and other LLM-based tools). Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.).
Exploitation Status
Active campaign confirmed. At least 15 malicious plugins distributed through official JetBrains Marketplace. Plugins designed to steal AI provider API keys and sensitive developer data upon installation.
Business Impact
Compromised API keys enable unauthorized access to AI services, potentially leading to financial loss from API abuse, data exfiltration from AI interactions, and exposure of proprietary code or intellectual property. Developer workstations may be compromised with additional payloads. Supply chain risk if stolen credentials provide access to development infrastructure or source code repositories.
Urgency
🔴 Immediate
Recommended Actions
- Audit all installed JetBrains IDE plugins immediately and remove any unverified AI assistant or DeepSeek-related plugins installed recently
- Rotate all AI provider API keys (OpenAI, Anthropic, DeepSeek, etc.) stored in JetBrains IDE settings or environment variables
- Review JetBrains IDE logs and network traffic for connections to unknown external domains from plugin activity
- Implement organizational policy requiring approval before installing third-party IDE plugins from JetBrains Marketplace
- Monitor API usage dashboards for AI services to detect anomalous consumption patterns indicating key compromise
