Skip to content
Illicit VS Code extension delivers multi-stage Evelyn infostealer

Illicit VS Code extension delivers multi-stage Evelyn infostealer

Scworld • January 21, 2026

Attackers have harnessed a malicious Visual Studio Code extension to deliver the multi-stage Evelyn information-stealing malware, reports Cyber Security News .

Installation of the trojanized VS Code add-on prompts the covert deployment of a counterfeit Lightshot.dll component, which when executed by LightShot.exe as users capture screenshots, launches a concealed PowerShell command that retrieves and runs a second-stage file, according to Trend Micro researchers. Apart from compromising browser passwords, cryptocurrency wallets, messaging sessions, cookies, VPN profiles, Wi-Fi keys, and other files, Evelyn Stealer also pilfers detailed system information to an attacker-controlled FTP server.

Researchers warned that the compromise of a lone developer laptop could result in the exposure of data, which could be weaponized to facilitate a sweeping network breach. Such findings come amid the increasingly prevalent exploitation of VS Code as an attacker platform.

Extracted Entities

Attack Types (2)

Malware (1)

MITRE ATT&CK (1)

Platforms (1)