logo

“Evelyn Stealer” Weaponizes Visual Studio Code Extensions

ID: d3a46baa-8b37-5ae7-aded-92dc52b9dbf2

STIX ID: report--d3a46baa-8b37-5ae7-aded-92dc52b9dbf2

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-21

Date Updated: 2026-04-23

Author: Ddos

...
...

Trend Micro analysis details the "Evelyn Stealer" campaign that weaponizes Visual Studio Code extensions to deliver a multi-stage information‑stealing malware. The campaign deploys loaders, uses process hollowing and DLL injection, employs AES-256-CBC encryption and anti-analysis techniques, and steals browser credentials, cryptocurrency data, screenshots, Wi‑Fi and clipboard information—targeting developers who often hold privileged access to production systems and cloud infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.