Malicious JetBrains Marketplace plugins steal AI API keys from developers
2026-06-17T01:23:33Z•1d6bb1c0c4c304b89994805944c0117b6bc64a526c43bd49d9db91ceb1214347
AI-api-keysCVE-2026-20262CVE-2026-54420Cisco SD‑WANDragonForceFortiSandboxFortinetGhostTreeJetBrains MarketplaceMicrosoft Teams relayNTFS-junctionOptinMonsterRokarollaSprySOCKS-windows variant (govt targeting)Steam WorkshopWallpaper EngineWordPressbanking-trojancredential-theftevasionexploitmalwareransomwaresupply-chainvulnerability
What happened
Multiple high-impact threats reported: actively exploited vulnerabilities in enterprise products (LiteSpeed cPanel plugin CVE-2026-54420 and Cisco SD‑WAN vManage CVE-2026-20262), critical Fortinet FortiSandbox flaws under exploitation, and widespread supply‑chain compromises (OptinMonster/WordPress CDN). Concurrent malware and fraud activity includes the Rokarolla Android banking trojan targeting 217 banking/crypto apps, JetBrains Marketplace plugins exfiltrating AI API keys, Steam Workshop wallpaper packages used to deliver malware, GhostTree NTFS junction evasion to bypass Defender scans, RY
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 1d6bb1c0c4c304b89994805944c0117b6bc64a526c43bd49d9db91ceb1214347
- Enrichment time
- 2026-06-17T01:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.