Anivia Stealer is a Windows information-stealing malware family observed in a multi-stage supply-chain style campaign involving a spoofed Prettier Code formatter extension on the VSCode Marketplace, including the malicious extension identified as "publishingsofficial.prettier-vscode-plus." According to the provided reporting, the fake extension launched a batch script that ran a Visual Basic Script to execute the stealer, with the payload chain designed to evade common anti-malware and static scanning tactics and to execute covertly in memory. Reported capabilities include theft and exfiltration of credentials, metadata, other sensitive private information, and WhatsApp chats from Windows machines. The malware was also reported to contain sandbox-evasion logic. Microsoft and the VSCode Marketplace removed the malicious extension shortly after disclosure, limiting impact to only a few users. Separate reporting cited in the content states that Anivia Stealer has previously been offered as a malware-as-a-service platform. High-confidence infection vector information in the content is limited to the malicious VSCode extension campaign targeting Windows users, particularly developers downloading tools from the marketplace.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Information-stealing malware delivered via a spoofed VSCode extension, executed covertly in-memory in a multi-stage chain; steals credentials, WhatsApp chats, and other sensitive data, and includes sandbox-evasion logic.
Anivia Stealer is an information stealer malware that exfiltrates credentials, metadata, and private information such as WhatsApp chats from Windows machines.
An information-stealing malware delivered via a malicious VSCode extension masquerading as a Prettier-related plugin.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.