15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers

Confirmed
Discovered Jun 19, 2026

StepSecurity and JetBrains say 15 malicious JetBrains Marketplace plugins stole AI provider API keys from developers, then a remote kill-switch and marketplace purge removed the listings and banned the publisher accounts.

10
Affected Packages
8
Observables
5
Sources

Timeline

1 of 1 rows

Timeline
DateEventDescriptionSource
Jun 19, 2026Fresh source reviewReviewed direct and primary sources for the last-two-weeks supply-chain refresh; this preview intentionally excludes older Halting Problems article data.Direct source

Affected Software

10 of 10 rows

Affected Software
PackageEcosystemVersion RangeStatusConfidenceSource
org.sm.yms.toolkitjetbrains-marketplaceunknownMalicious90%Direct source
com.json.simple.kitjetbrains-marketplaceunknownMalicious90%Direct source
org.bug.find.toolsjetbrains-marketplaceunknownMalicious90%Direct source
org.translate.ai.simplejetbrains-marketplaceunknownMalicious90%Direct source
com.yy.test.ai.simplejetbrains-marketplaceunknownMalicious90%Direct source
com.dev.ai.toolkitjetbrains-marketplaceunknownMalicious90%Direct source
com.json.view.simplejetbrains-marketplaceunknownMalicious90%Direct source
com.my.git.ai.kitjetbrains-marketplaceunknownMalicious90%Direct source
org.check.ai.dsjetbrains-marketplaceunknownMalicious90%Direct source
com.review.tool.codejetbrains-marketplaceunknownMalicious90%Direct source

IOC Clipboard

8 IOCs
urlhttp://39.107.60.51/api/software/key
urlhttp://39.107.60.51/api/software/check
urlhttps://www.stepsecurity.io/blog/jetbrains-malicious-plugins-ai-api-key-theft
urlhttps://blog.jetbrains.com/platform/2026/06/marketplace-ecosystem-security-update-malicious-ai-plugins/
urlhttps://plugins.jetbrains.com/plugin/org.sm.yms.toolkit
urlhttps://plugins.jetbrains.com/plugin/com.json.simple.kit
ip39.107.60.51
commandJetBrains IDE process sending HTTP POST requests to 39.107.60.51

Provenance & Sources

5 of 5 rows

Provenance & Sources
SourceTypeReliabilityClaimsEvidence
Direct sourcedirect95%1https://blog.jetbrains.com/platform/2026/06/marketplace-ecosystem-security-update-malicious-ai-plugins/
Primary researchprimary research95%1https://www.stepsecurity.io/blog/jetbrains-malicious-plugins-ai-api-key-theft
Primary researchprimary research95%1https://plugins.jetbrains.com/plugin/org.sm.yms.toolkit
Primary researchprimary research95%1https://plugins.jetbrains.com/plugin/com.json.simple.kit
Primary researchprimary research95%1https://plugins.jetbrains.com/plugin/com.dp.git.ai.tool