JetBrains Marketplace Supply Chain Attack: 15 Malicious AI Plugins & API Key Exfiltration
Security researchers uncovered a serious supply chain attack targeting JetBrains Marketplace, where 15 malicious AI plugins were disguised as legitimate DeepSeek AI assistants. This attack not only harvested API keys but also exfiltrated chat sessions from large language models, ensuring persistent access to development environments. The implications are significant, as this breach could affect downstream applications and developer tools, raising serious concerns about data security and the integrity of software supply chains.
Original Source
Read the full article at Dev →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.