Malicious VS Code Extension Distributes Evelyn Infostealer Malware

Malicious VS Code Extension Distributes Evelyn Infostealer Malware

First seen 22 Jan 2026, 02:59 UTC ScworldBleepingcomputer 69% similarity 50.4

Article Content

Browse articles
ThreatCluster

Attackers have exploited a malicious Visual Studio Code extension to deploy the Evelyn infostealer malware. The installation of the compromised add-on triggers the covert deployment of a fake Lightshot.dll component, which executes a PowerShell command to retrieve and run a second-stage file. This attack primarily affects users of the LightShot screenshot tool.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story