logo

Visual Studio Code Abused in Sophisticated Multistage Malware Attacks

ID: c2188acc-ec73-5257-80b0-0b5a89b159bd

STIX ID: report--c2188acc-ec73-5257-80b0-0b5a89b159bd

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-01-19

Date Updated: 2026-06-18

Author: Mayura Kathir

...
...

**Executive summary:** The Evelyn Stealer campaign weaponizes seemingly legitimate Visual Studio Code extensions (e.g., themes and AI assistants) to run PowerShell/batch stagers that sideload a trojanized Lightshot DLL, deploy a process-hollowing second stage (iknowyou.model) which decrypts and runs the Evelyn Stealer payload, performs extensive anti-analysis checks, harvests browser credentials, cookies, clipboard, wallet data and system artifacts, packages them into contextual ZIPs, and exfiltrates data over FTP — posing a high risk to developer systems, source code, secrets, and enterprise CI/CD pipelines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.