Skip to content
Malicious VS Code Extension Distributes Evelyn Infostealer Malware

Malicious VS Code Extension Distributes Evelyn Infostealer Malware

First seen 22 Jan 2026, 02:59 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

Attackers have exploited a malicious Visual Studio Code extension to deploy the Evelyn infostealer malware. The installation of the compromised add-on triggers the covert deployment of a fake Lightshot.dll component, which executes a PowerShell command to retrieve and run a second-stage file. This attack primarily affects users of the LightShot screenshot tool.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 198d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Evelyn Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed