15 Malicious JetBrains Plugins Caught Stealing DeepSeek, OpenAI API Keys

2026-06-17T08:51:46Z26f697ab190d860c2b5f813b7f91316dca02c41febc9402ab79e9eaa147bc423
agent-identity-securityamos-stealerandroid-trojanapi-key-theftcalifornia-water-servicecopilot-studiodata-breachdeepfakesdeepseekhandalajetbrains-pluginsmacos-keychainmagicadopenairokarolla

What happened

Multiple active threats and notable security developments: 15 malicious JetBrains plugins posing as AI coding assistants have been observed stealing developer API keys (DeepSeek, OpenAI, etc.). Amos Stealer campaigns target macOS users to exfiltrate Keychain files, browser passwords, cookies and developer configs. Mobile threats include the Rokarolla Android trojan (targeting 217 crypto and banking apps) and 50+ Android apps spreading the MagicAd trojan to force background ads and hijack devices. Threat actor Handala claims a breach of California Water Service with ~5GB of leaked customer/GPS/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
26f697ab190d860c2b5f813b7f91316dca02c41febc9402ab79e9eaa147bc423
Enrichment time
2026-06-17T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.