Evelyn Stealer Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
January 19, 2026
Last Seen
February 16, 2026

Related Threat Clusters

  • Malicious VS Code Extension Distributes Evelyn Infostealer Malware

    Attackers have exploited a malicious Visual Studio Code extension to deploy the Evelyn infostealer malware. The installation of the compromised add-on triggers the covert deployment of a fake Lightshot.dll component,…

    2 articles · Updated January 21, 2026
  • OpenClaw Ecosystem Faces Ongoing Security Vulnerabilities

    The OpenClaw ecosystem, previously known as ClawdBot and Moltbot, is experiencing significant security vulnerabilities, including bot takeover and remote code execution (RCE) exploits. Security researchers, including…

    299 articles · Updated February 2, 2026
  • Visual Studio Code Exploited for Multistage Malware Deployment

    Threat actors are utilizing Visual Studio Code to deploy a sophisticated multistage malware campaign known as Evelyn Stealer. This malware is delivered through a malicious extension that targets developer workstations,…

    4 articles · Updated January 19, 2026

Recent Intelligence Reports

  • Infostealer Targets OpenClaw Configurations and Keys — Technadu · February 16, 2026
  • Illicit VS Code extension delivers multi-stage Evelyn infostealer — Scworld · January 21, 2026
  • Threat Actors Weaponizing Visual Studio Code to Deploy a Multistage Malware — Cybersecuritynews · January 19, 2026

CVSS v3.1 Breakdown