JetBrains Platform A.I CyberSecurity Scoring
JetBrains Platform
Company Information
Website:https://plugins.jetbrains.com/
Employees number:None
Number of followers:1,101
NAICS:5112
Industry Type:Software Development
Homepage:jetbrains.com
JetBrains Platform Risk Score (AI oriented)
Between 700 and 749
JetBrains PlatformSoftware Development
Updated:
16/06/2026
16/06/2026
727/1000
Moderate
Ba
JetBrains Platform Global Score (TPRM)
xxxx
JetBrains PlatformSoftware Development
Score locked

JetBrains PlatformModerate
Current Score
727Ba (MODERATE)
01000
1 incidents
-26 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
753
Cyber Attack
16 Jun 2026 • JetBrains Platform
JetBrains, DeepSeek and OpenAI: Malicious JetBrains Marketplace plugins steal AI API keys from developers
Malicious JetBrains Plugins Steal AI API Keys in Large-Scale Campaign
727
CRITICAL-26
JETOPEDEE1781648632
Malicious JetBrains Plugins Steal AI API Keys in Large-Scale Campaign
Security researchers at Aikido Security uncovered a coordinated malware campaign targeting developers via the JetBrains Marketplace, where at least 15 malicious plugins were designed to steal AI API keys from users. The plugins, disguised as legitimate AI coding assistants, code-review tools, and Git utilities, exploited integrations with services like OpenAI, DeepSeek, and SiliconFlow to harvest credentials.
First published in October 2025, the plugins continued to appear as recently as June 10, 2026, with nearly 70,000 cumulative downloads. While functioning as advertised, they secretly transmitted API keys to a hardcoded server (39.107.60[.]51) via HTTP when users saved their credentials. All 15 plugins shared near-identical malicious code, despite being listed under seven different vendor accounts.
Notably, the plugins offered a paid tier after users paid a small fee, the server provided an API key for model calls, replacing the user’s own credentials. Aikido Security noted this behavior was unusual, as legitimate operators would not distribute unrestricted paid API keys.
The most downloaded plugins DeepSeek AI Assist (27,727 downloads) and CodeGPT AI Assistant (25,571 downloads) remained available on the Marketplace at the time of reporting. However, researchers cautioned that download counts could be inflated. BleepingComputer independently verified the credential-theft code in the DeepSeek AI Assist plugin.
While malicious packages are common on platforms like npm and PyPI, such campaigns are rare on the JetBrains Marketplace. JetBrains had not responded to inquiries at the time of publication. The full list of compromised plugins includes tools like DeepSeek Git Commit, AI Coder Review, and Coding Simple Tool.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
753
APRIL 2026
753
MARCH 2026
753
FEBRUARY 2026
753
JANUARY 2026
753
DECEMBER 2025
753
NOVEMBER 2025
753
OCTOBER 2025
753
SEPTEMBER 2025
753
AUGUST 2025
753
JULY 2025
753
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for JetBrains Platform ??
What was JetBrains Platform's A.I Rankiteo Cyber Score in May 2026 ??
What was JetBrains Platform's A.I Rankiteo Cyber Score in April 2026 ??
What was JetBrains Platform's A.I Rankiteo Cyber Score in March 2026 ??
What was JetBrains Platform's A.I Rankiteo Cyber Score in February 2026 ??
What was JetBrains Platform's A.I Rankiteo Cyber Score in January 2026 ??
What was JetBrains Platform's A.I Rankiteo Cyber Score in December 2025 ??
What was JetBrains Platform's A.I Rankiteo Cyber Score in November 2025 ??
What was JetBrains Platform's A.I Rankiteo Cyber Score in October 2025 ??
What was JetBrains Platform's A.I Rankiteo Cyber Score in September 2025 ??
What was JetBrains Platform's A.I Rankiteo Cyber Score in August 2025 ??
What was JetBrains Platform's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on JetBrains Platform's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with JetBrains Platform ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view JetBrains Platform's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?