Trend Micro reported a multi-stage information-stealing campaign, dubbed Evelyn Stealer, that targets software developers by weaponizing the Visual Studio Code extension ecosystem. The operation relies on trojanized extensions as an initial access vector into developer environments, then uses staged loaders and stealth techniques (including process hollowing, DLL injection, and anti-analysis measures) to execute the infostealer and evade detection; Trend Micro noted the use of strong cryptography such as AES-256-CBC as part of the malware’s operational security.
Once established, Evelyn Stealer focuses on harvesting high-value data commonly present on developer workstations, including browser credentials and cookies, cryptocurrency wallet data, screenshots, clipboard contents, Wi‑Fi details, and other sensitive artifacts that can enable broader compromise. Reporting also describes a specific execution chain in which a malicious extension drops a fake Lightshot.dll that is loaded by LightShot.exe, triggering a hidden PowerShell command to fetch and run a second-stage payload; stolen data and system details are then exfiltrated to attacker infrastructure (including an attacker-controlled FTP server). Researchers warned that compromising even a single developer endpoint could expose credentials and access paths that enable follow-on intrusion into production systems, cloud environments, and wider enterprise networks.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
The reporting detailed that after installation, the malicious extension drops a fake Lightshot.dll executed by LightShot.exe, which launches hidden PowerShell to retrieve a second-stage payload using techniques including process hollowing and DLL injection. Evelyn steals browser credentials, cryptocurrency wallet data, messaging sessions, cookies, VPN profiles, Wi-Fi keys, screenshots, clipboard contents, and system information, then exfiltrates the data to an attacker-controlled FTP server.
Trend Micro reported a multi-stage malware campaign dubbed Evelyn Stealer that targets software developers by disguising malicious payloads as Visual Studio Code extensions. The campaign uses the developer environment as the initial access vector to infect development machines.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.