← Back to Daily Briefing

A sophisticated multi-vector campaign is targeting the "vibe coding" ecosystem by exploiting the AI-integrated development lifecycle to exfiltrate high-value secrets. Attackers are deploying malicious plugins within the JetBrains Marketplace to harvest LLM API keys and utilizing Google Ads to direct developers toward weaponized Claude.ai and ChatGPT shared links. These links facilitate the delivery of cookie-stealing malware and session-hijacking extensions to bypass MFA. Additionally, vulnerabilities in the Model Context Protocol (MCP) within Amazon Q allow for unauthorized code execution and cloud credential theft. This campaign represents a critical risk to developer environments, targeting both the IDE supply chain and browser-based sessions to achieve mass exfiltration of cloud and AI provider credentials.

  • Attack Vector I: IDE Supply Chain Compromise

    • Distribution of approximately 15 malicious plugins in the JetBrains Marketplace masquerading as AI coding assistants (e.g., DeepSeek-based tools).
    • Implementation of embedded exfiltration modules designed to intercept environment variables and configuration files containing LLM API secrets.
    • Exploitation of the Model Context Protocol (MCP) in Amazon Q to facilitate unauthorized remote code execution (RCE) and subsequent cloud credential theft.
  • Attack Vector II: Browser-Based Interception and Malvertising

    • Use of Google Ads to funnel developers toward fraudulent AI tool download sites or weaponized "outage" pages.
    • Weaponization of trusted domains by hijacking Claude.ai and ChatGPT shared chat links to host malicious payloads or phishing redirects.
    • Deployment of session-hijacking extensions and cookie-stealing malware to bypass MFA and seize active developer sessions.
  • Scale of Impact and Operational Risk

    • Initial malvertising phase identified over 2,000 victims, with estimates suggesting up to 70,000 developers exposed via malicious plugins.
    • Critical operational risk of full cloud environment takeover stemming from unauthorized RCE via MCP vulnerabilities in Amazon Q.
    • High probability of widespread API key leakage for major AI providers, enabling unauthorized resource consumption and data access.
  • Defensive Actions and Mitigations

    • Audit all installed JetBrains plugins for unauthorized network traffic and verify plugin provenance and digital signatures.
    • Implement strict access controls and continuous monitoring for Model Context Protocol (MCP) configurations within Amazon Q environments.
    • Deploy hardware-based MFA (FIDO2/WebAuthn) to mitigate the efficacy of cookie-stealing and session-hijacking attacks.
    • Enforce organizational policies restricting the execution of unsigned binaries downloaded via ad-driven redirects.

Related posts

  1. techjacksolutions.com — Dual AI Credential Theft Campaign: JetBrains Plugin Supply Chain and Chrome Extension Interception Target Developer Secrets and Chatbot Data
  2. Pushsecurity
  3. Trend Micro Simply Security — Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign
  4. thehackernews.com — Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats
  5. Aws
  6. Sosdailynews
  7. Bleepingcomputer
  8. Labs
  9. Croninity
  10. Wiz
  11. Threat-modeling
  12. Pillar
  13. Stepsecurity
  14. Youtube
  15. 1000i

LINK COPIED TO CLIPBOARD