AIO APEX

News

Breaking news and updates from the world of technology.

15 malicious JetBrains plugins spent 8 months stealing developers' AI API keys
Security

15 malicious JetBrains plugins spent 8 months stealing developers' AI API keys

Attackers published 15 fake AI coding plugins on the JetBrains Marketplace under seven vendor accounts, collectively downloaded nearly 70,000 times. Each plugin silently exfiltrated OpenAI, DeepSeek, and SiliconFlow API keys to an attacker-controlled server.

BleepingComputer
api-keyssupply-chain-attack