Credential theft scales with credential value, and AI API keys — especially for models at the frontier — are now worth stealing at volume. The JetBrains Marketplace attack succeeded because it exploited a trust relationship developers rarely scrutinize: an IDE plugin feels like infrastructure, not an external service. Once installed, such a plugin operates inside the same process as live coding sessions, with access to environment variables, config files, and any tokens cached in memory.
The T2I-CompBench++ evaluation framework for generative model compositionality and projects extending local LLM tool-calling — such as agentic Ollama integration for real-world actions