News Radar RSS

Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

The Hacker News Cybersecurity Score 7/10

Summary

Cybersecurity researchers have flagged a "coordinated malware campaign" on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys. "Every plugin poses as an AI coding assistant built on DeepSeek and other large language models, offering chat, commit messages, code review, bug finding, and unit tests,"

SecurityThreat Intel

News Radar provides aggregated summaries. Full content and copyright remain with the original publisher.