JetBrains, Amazon Q, and Claude.ai Targeted in Dual AI-Driven Credential Theft Campaign
A sophisticated multi-vector campaign is targeting the "vibe coding" ecosystem by exploiting the AI-integrated development lifecycle to exfiltrate high-value secrets. Attackers are deploying malicious plugins within the JetBrains Marketplace to harvest LLM API keys and utilizing Google Ads to direct developers toward weaponized Claude.ai and ChatGPT shared links. These links facilitate the delivery of cookie-stealing malware and session-hijacking extensions to bypass MFA. Additionally, vulnerabilities in the Model Context Protocol (MCP) within Amazon Q allow for unauthorized code execution and cloud credential theft. This campaign represents a critical risk to developer environments, targeting both the IDE supply chain and browser-based sessions to achieve mass exfiltration of cloud and AI provider credentials.