discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats

Malicious plugins on the JetBrains Marketplace have been stealing AI API keys, while Chrome extensions have been capturing AI chatbot conversations.

By Ravie Lakshmanan·Jun 17·thehackernews.com·2 min read

Intelligence analysis by Llama 3.3 70B

Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
Image: thehackernews.com

A coordinated malware campaign has been discovered on the JetBrains Marketplace, with 15 malicious plugins exfiltrating AI provider keys, and two Chrome extensions capturing AI chatbot conversations.

Why it matters

The discovery highlights the increasing threat of malware campaigns targeting developer environments and AI services, compromising sensitive information and potentially leading to illicit monetization schemes.

Imagine you're using a tool to help you code, and it asks for a special key to access a powerful AI service. But instead of just using the key for the tool, it secretly sends the key to a bad guy's server, who can then use it to access the AI service without your permission. That's what's happening with some malicious plugins and Chrome extensions.

Analysis

Malicious Plugins on JetBrains Marketplace

The JetBrains Marketplace has been compromised by a coordinated malware campaign, with 15 malicious plugins discovered to be exfiltrating AI provider keys. These plugins, which pose as AI coding assistants, have been found to work as intended but also sneak in the ability to covertly siphon the provided API key to a remote server. The plugins require users to enter an API key for an AI service, which is then transmitted to the attacker's server in plaintext format.

The campaign is said to have been ongoing since October 2025, with new plugins released as recently as June 10, 2026. Two of the plugins, CodeGPT AI Assistant and DeepSeek AI Assist, have more than 25,000 downloads each, although the authenticity of these download counts is unclear.

Chrome Extensions Capturing AI Conversations

In a related development, two Google Chrome ad blocker extensions have been caught capturing users' conversations with AI chatbots. The extensions, Smart Adblocker and Adblock for Browser, have been found to ship a custom-built interception engine that records non-public conversations, model usage, and account-tier metadata from every major AI platform.

The extensions have been around for several years, indicating that the AI-related data exfiltration features were introduced in the form of software updates. This type of attack falls under the category of Prompt Poaching, where browser extensions stealthily capture users' AI chats under the pretext of enhancing Safe Browsing or providing in-depth traffic or engagement metrics.

Implications and Recommendations

The discovery of these malicious plugins and Chrome extensions highlights the need for developers and users to be cautious when installing and using third-party tools and extensions. It is essential to treat plugins and extensions with the same level of scrutiny as any dependency that runs with privileges, and to be cautious about pasting long-lived secrets into tools that have not been vetted. Users should also be aware of the potential risks of using AI services and take steps to protect their sensitive information.

Key points

  • 15 malicious plugins discovered on JetBrains Marketplace
  • Plugins exfiltrate AI provider keys
  • Two Chrome extensions capture AI chatbot conversations
  • Extensions have been around for several years
  • Users should be cautious when installing and using third-party tools and extensions
The Upside

The discovery of these malicious plugins and Chrome extensions highlights the importance of vigilance and caution when using third-party tools and extensions. By being aware of the potential risks and taking steps to protect sensitive information, users can help prevent the spread of malware and protect their AI services.

The Downside

The fact that these malicious plugins and Chrome extensions were able to operate undetected for so long raises concerns about the effectiveness of current security measures. If left unchecked, these types of attacks could lead to widespread compromise of sensitive information and potentially devastating consequences for individuals and organizations.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagsai-securityapi-key-theftbrowser-extensionchromedeveloper-securityjetbrainsllmjackingmalwareprompt-poachingsupply-chain-security

Author

Ravie Lakshmanan

Intelligence analysis by

Llama 3.3 70B

Published

Jun 17, 2026

Source

thehackernews.com

Share

Topics

ai-securityapi-key-theftbrowser-extensionchromedeveloper-securityjetbrainsllmjackingmalwareprompt-poachingsupply-chain-security

Related

More from this desk

Aug 18·wired.com

The Cop Who Took On Flock

A police officer in Rhode Island discovers that his city has installed Flock Safety cameras, which can identify vehicles by their license plates and other distinguishing features. The officer's concerns about the cameras' potential for mass surveillance lead to a chain of…

Aug 18·bleepingcomputer.com

Microsoft Confirms Outage Affecting Search in Microsoft 365 Apps

Microsoft confirms that some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. The root cause is a recent deployment that causes resource utilization problems.

Aug 18·thehackernews.com

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

SafePal, a hardware wallet maker, has disclosed an authorization flaw in an order-tracking plug-in that exposed the data of nearly 40,000 customers. The exposed records included names, email addresses, shipping addresses, phone numbers, and purchase details, but did not i…

Aug 18·bleepingcomputer.com

Microsoft Removes WMIC Tool Used by Cybercriminals

Microsoft has removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. This move aims to improve the operating system's overall security by thwarting a wide range of m…