Scworld
Malicious VS Code Extension Distributes Evelyn Infostealer Malware
First seen 22 Jan 2026, 02:59 UTC
•
•69% similarity
•50.4
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Attackers have exploited a malicious Visual Studio Code extension to deploy the Evelyn infostealer malware. The installation of the compromised add-on triggers the covert deployment of a fake Lightshot.dll component, which executes a PowerShell command to retrieve and run a second-stage file. This attack primarily affects users of the LightShot screenshot tool.
ThreatCluster AI
How this analysis works