Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A coordinated supply chain campaign planted at least 15 malicious plugins in the JetBrains Marketplace over eight months, accumulating nearly 70,000 installs before discovery by Aikido Security. The plugins silently harvested AI provider API keys for OpenAI, DeepSeek, and SiliconFlow and transmitted them in plaintext to attacker-controlled servers. Organizations with developers using JetBrains IntelliJ-based IDEs face immediate risk of AI service account takeover, unauthorized API cost charges, and potential exposure of proprietary code or data submitted through compromised AI integrations.

Author

Tech Jacks Solutions