Jetbrains should point out that any compromised build server could be used to inject malicious code into enterprise apps. So far, that is the story, no credible sign that, say, a Jetbrains installer was the payload.
https://blog.jetbrains.com/blog/2021/01/06/statement-on-the-story-from-the-new-york-times-regarding-jetbrains-and-solarwinds/
Post
January 7, 2021