Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
JetBrains Platform

JetBrains Platform Vendor Cyber Rating & Cyber Score

jetbrains.com

Here, you'll find developer-focused content about JetBrains Marketplace, along with updates about plugins developed by our community of plugin creators. Join us in enhancing the global developer experience by building and distributing plugins for developers like you. SHARE YOUR EXPERTISE WITH THE COMMUNITY If you've written anything about plugin development, recorded a video about it, or wanted to share a hidden gem you discovered on JetBrains Marketplace – let us know! Submit content you'd like us to consider reposting by filling out this form: jb.gg/mp-content-form


JetBrains Platform A.I CyberSecurity Scoring

JetBrains Platform
Company Information
Website:https://plugins.jetbrains.com/
Employees number:None
Number of followers:1,101
NAICS:5112
Industry Type:Software Development
Homepage:jetbrains.com
JetBrains Platform Risk Score (AI oriented)
Between 700 and 749
logo
JetBrains PlatformSoftware Development
Updated:
16/06/2026
727/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
JetBrains Platform Global Score (TPRM)
xxxx
logo
JetBrains PlatformSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

JetBrains Platform
JetBrains PlatformModerate
Current Score
727Ba (MODERATE)
01000
1 incidents
-26 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
753Before Incident
Cyber Attack
16 Jun 2026JetBrains Platform
JetBrains, DeepSeek and OpenAI: Malicious JetBrains Marketplace plugins steal AI API keys from developers

Malicious JetBrains Plugins Steal AI API Keys in Large-Scale Campaign

727After Incident
CRITICAL-26
JETOPEDEE1781648632
Malicious JetBrains Plugins Steal AI API Keys in Large-Scale Campaign Security researchers at Aikido Security uncovered a coordinated malware campaign targeting developers via the JetBrains Marketplace, where at least 15 malicious plugins were designed to steal AI API keys from users. The plugins, disguised as legitimate AI coding assistants, code-review tools, and Git utilities, exploited integrations with services like OpenAI, DeepSeek, and SiliconFlow to harvest credentials. First published in October 2025, the plugins continued to appear as recently as June 10, 2026, with nearly 70,000 cumulative downloads. While functioning as advertised, they secretly transmitted API keys to a hardcoded server (39.107.60[.]51) via HTTP when users saved their credentials. All 15 plugins shared near-identical malicious code, despite being listed under seven different vendor accounts. Notably, the plugins offered a paid tier after users paid a small fee, the server provided an API key for model calls, replacing the user’s own credentials. Aikido Security noted this behavior was unusual, as legitimate operators would not distribute unrestricted paid API keys. The most downloaded plugins DeepSeek AI Assist (27,727 downloads) and CodeGPT AI Assistant (25,571 downloads) remained available on the Marketplace at the time of reporting. However, researchers cautioned that download counts could be inflated. BleepingComputer independently verified the credential-theft code in the DeepSeek AI Assist plugin. While malicious packages are common on platforms like npm and PyPI, such campaigns are rare on the JetBrains Marketplace. JetBrains had not responded to inquiries at the time of publication. The full list of compromised plugins includes tools like DeepSeek Git Commit, AI Coder Review, and Coding Simple Tool.
INCIDENT DETAILS -
TYPE
Malware Campaign
MOTIVATION
Credential theft, potential financial gain from stolen API keys
IMPACT
Data Compromised: AI API keys (OpenAI, DeepSeek, SiliconFlow)Systems Affected: Developer environments using JetBrains pluginsOperational Impact: Potential unauthorized access to AI services using stolen credentialsBrand Reputation Impact: Potential reputational damage to JetBrains Marketplace and affected AI service providers
DATA BREACH
Type Of Data Compromised: AI API keysNumber Of Records Exposed: Nearly 70,000 potential exposures (plugin downloads)Sensitivity Of Data: High (API keys for AI services)Data Exfiltration: Yes (transmitted to hardcoded server 39.107.60[.]51)
MAY 2026
753Before Incident
APRIL 2026
753Before Incident
MARCH 2026
753Before Incident
FEBRUARY 2026
753Before Incident
JANUARY 2026
753Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
753Before Incident
OCTOBER 2025
753Before Incident
SEPTEMBER 2025
753Before Incident
AUGUST 2025
753Before Incident
JULY 2025
753Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for JetBrains Platform ?
?
What was JetBrains Platform's A.I Rankiteo Cyber Score in May 2026 ?
?
What was JetBrains Platform's A.I Rankiteo Cyber Score in April 2026 ?
?
What was JetBrains Platform's A.I Rankiteo Cyber Score in March 2026 ?
?
What was JetBrains Platform's A.I Rankiteo Cyber Score in February 2026 ?
?
What was JetBrains Platform's A.I Rankiteo Cyber Score in January 2026 ?
?
What was JetBrains Platform's A.I Rankiteo Cyber Score in December 2025 ?
?
What was JetBrains Platform's A.I Rankiteo Cyber Score in November 2025 ?
?
What was JetBrains Platform's A.I Rankiteo Cyber Score in October 2025 ?
?
What was JetBrains Platform's A.I Rankiteo Cyber Score in September 2025 ?
?
What was JetBrains Platform's A.I Rankiteo Cyber Score in August 2025 ?
?
What was JetBrains Platform's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on JetBrains Platform's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with JetBrains Platform ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view JetBrains Platform's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?