Anivia is a C# malware loader observed in a multi-stage supply-chain attack delivered through the malicious Visual Studio Code extension "prettier-vscode-plus" on the official VSCode Marketplace in November 2025. In the documented chain, a VBScript dropper launched a PowerShell payload containing an AES-encrypted blob; that PowerShell stage decrypted and executed Anivia in memory. Anivia then decrypted and injected the OctoRAT payload into the legitimate vbc.exe process using process hollowing. Reported protections and evasion behavior include AES-256-CBC encryption with PKCS7 padding, in-memory execution, and process hollowing into vbc.exe. The campaign impersonated the legitimate Prettier formatter and targeted developers via the VSCode extension ecosystem. It was attributed in reporting by Checkmarx Zero and Hunt Intelligence/Hunt.io as part of a broader malware chain whose final payload, OctoRAT, supports credential theft and remote access. High-confidence detection opportunities directly mentioned for this chain include monitoring for the malicious "prettier-vscode-plus" extension, suspicious GitHub payload hosting/access, and vbc.exe process hollowing. The provided content states that indicators of compromise include hashes for the Anivia loader, but does not enumerate those hashes in the supplied material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader stage used to decrypt payloads in memory (AES) and execute them via process hollowing (into vbc.exe), leading to OctoRAT deployment.
Anivia is a C#-based loader and stealer that acts as a second-stage payload in a multi-stage attack chain. It decrypts and executes further payloads (notably OctoRAT) in memory using AES-256, and employs process hollowing to inject into legitimate Windows processes. It is also capable of credential and data theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.