Researchers from Aikido Security report that at least 15 malicious plugins are listed on the JetBrains Marketplace and are designed to steal AI API keys from developers. The plugins are presented as tools such as AI coding assistants that work with large language models, including offerings framed around chat features and development workflows like commit messages, code review, bug finding, and unit tests. According to the reporting, the campaign is coordinated, and the malicious behavior focuses on exfiltrating authentication material that developers use to access AI services. The Hacker News and Bleeping Computer both describe the same core issue: multiple plugins masquerade as legitimate AI-related IDE extensions, while actually capturing and attempting to transmit sensitive API credentials. The sources indicate that the number of identified malicious plugins is at least 15, though researchers may continue to expand the list.