Home / Companies / JetBrains / Blog / Post Details
Content Deep Dive

JetBrains Marketplace Ecosystem Security Update: Addressing Malicious Third-Party AI Plugins - The JetBrains Blog

Blog post from JetBrains

Post Details
Company
Date Published
Author
Jakub Chrzanowski
Word Count
1,118
Company Posts That Month
53
Language
American English
Hacker News Points
-
Post removed?
No
Summary

On June 16, 2026, JetBrains identified a security breach involving 15 third-party plugins on its Marketplace, which were designed to steal AI provider API keys by masquerading as legitimate utilities. In response, the company removed the malicious plugins, banned the associated publisher accounts, and activated a remote mechanism to disable the plugins in users' IDEs. Despite the breach, JetBrains confirmed that its core systems remained uncompromised. The threat actors exploited a specific vulnerability by disabling TLS warnings and exfiltrating API keys to a hardcoded IP address. In the aftermath, JetBrains emphasized the importance of security diligence, instructed affected users to revoke exposed API keys, and introduced new security measures to prevent similar incidents. The company is advocating for the adoption of the Agent Client Protocol (ACP) registry to enhance security in AI workflows by standardizing communication between IDEs and external tools.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Coding Assistant 1 2,234 577 171 +12%
Secrets Management 1 2,539 400 136 +9%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.