Malicious JetBrains Marketplace plugins steal AI API keys from developers

2026-06-17T01:23:33Z1d6bb1c0c4c304b89994805944c0117b6bc64a526c43bd49d9db91ceb1214347
AI-api-keysCVE-2026-20262CVE-2026-54420Cisco SD‑WANDragonForceFortiSandboxFortinetGhostTreeJetBrains MarketplaceMicrosoft Teams relayNTFS-junctionOptinMonsterRokarollaSprySOCKS-windows variant (govt targeting)Steam WorkshopWallpaper EngineWordPressbanking-trojancredential-theftevasionexploitmalwareransomwaresupply-chainvulnerability

What happened

Multiple high-impact threats reported: actively exploited vulnerabilities in enterprise products (LiteSpeed cPanel plugin CVE-2026-54420 and Cisco SD‑WAN vManage CVE-2026-20262), critical Fortinet FortiSandbox flaws under exploitation, and widespread supply‑chain compromises (OptinMonster/WordPress CDN). Concurrent malware and fraud activity includes the Rokarolla Android banking trojan targeting 217 banking/crypto apps, JetBrains Marketplace plugins exfiltrating AI API keys, Steam Workshop wallpaper packages used to deliver malware, GhostTree NTFS junction evasion to bypass Defender scans, RY

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
1d6bb1c0c4c304b89994805944c0117b6bc64a526c43bd49d9db91ceb1214347
Enrichment time
2026-06-17T01:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.