Affected Systems

JetBrains Marketplace users who installed any of 15+ malicious plugins impersonating AI coding assistants (DeepSeek and other LLM-based tools). Affects developers using JetBrains IDEs (IntelliJ IDEA, PyCharm, WebStorm, etc.).

Exploitation Status

Active campaign confirmed. At least 15 malicious plugins distributed through official JetBrains Marketplace. Plugins designed to steal AI provider API keys and sensitive developer data upon installation.

Business Impact

Compromised API keys enable unauthorized access to AI services, potentially leading to financial loss from API abuse, data exfiltration from AI interactions, and exposure of proprietary code or intellectual property. Developer workstations may be compromised with additional payloads. Supply chain risk if stolen credentials provide access to development infrastructure or source code repositories.

Urgency

🔴 Immediate

Recommended Actions

  • Audit all installed JetBrains IDE plugins immediately and remove any unverified AI assistant or DeepSeek-related plugins installed recently
  • Rotate all AI provider API keys (OpenAI, Anthropic, DeepSeek, etc.) stored in JetBrains IDE settings or environment variables
  • Review JetBrains IDE logs and network traffic for connections to unknown external domains from plugin activity
  • Implement organizational policy requiring approval before installing third-party IDE plugins from JetBrains Marketplace
  • Monitor API usage dashboards for AI services to detect anomalous consumption patterns indicating key compromise