15 Malicious JetBrains Plugins Caught Stealing DeepSeek, OpenAI API Keys
2026-06-17T08:51:46Z•26f697ab190d860c2b5f813b7f91316dca02c41febc9402ab79e9eaa147bc423
agent-identity-securityamos-stealerandroid-trojanapi-key-theftcalifornia-water-servicecopilot-studiodata-breachdeepfakesdeepseekhandalajetbrains-pluginsmacos-keychainmagicadopenairokarolla
What happened
Multiple active threats and notable security developments: 15 malicious JetBrains plugins posing as AI coding assistants have been observed stealing developer API keys (DeepSeek, OpenAI, etc.). Amos Stealer campaigns target macOS users to exfiltrate Keychain files, browser passwords, cookies and developer configs. Mobile threats include the Rokarolla Android trojan (targeting 217 crypto and banking apps) and 50+ Android apps spreading the MagicAd trojan to force background ads and hijack devices. Threat actor Handala claims a breach of California Water Service with ~5GB of leaked customer/GPS/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 26f697ab190d860c2b5f813b7f91316dca02c41febc9402ab79e9eaa147bc423
- Enrichment time
- 2026-06-17T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.