Evelyn Stealer Malware Exploits VS Code Extensions to Steal Developer Data
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The Evelyn Stealer malware campaign has been identified as a significant threat to software developers, particularly those using Microsoft Visual Studio Code (VS Code) and its extensions. Discovered in January 2026, this malware is designed to extract sensitive information from compromised developer environments, including credentials and cryptocurrency-related data. Trend Micro reported that the malware exploits three specific VS Code extensions: BigBlack.bitcoin-black, BigBlack.codo-ai, and BigBlack.mrbigblacktheme, which deploy a malicious downloader DLL named “Lightshot.dll”.
This downloader executes a hidden PowerShell command to fetch and run a second-stage payload called “runtime.exe.” This executable injects the main stealer payload into a legitimate Windows process, enabling the malware to harvest various types of sensitive data. The data collected includes clipboard content, installed applications, cryptocurrency wallets, running processes, desktop screenshots, stored Wi-Fi credentials, system information, and credentials from browsers like Google Chrome and Microsoft Edge.
The malware employs sophisticated techniques to evade detection, such as checking for analysis environments and terminating active browser processes. It also uses command-line flags to run browsers in a stealthy manner, minimizing the risk of detection during data collection. This operational approach highlights the growing trend of targeting developer communities, which are increasingly seen as high-value targets in the cybersecurity landscape.
Implications for Developers and Organizations
The emergence of Evelyn Stealer underscores the need for heightened security awareness among software developers and organizations. Developers should be cautious when using third-party extensions and ensure they are sourced from reputable providers. The malware’s ability to collect sensitive data poses a direct threat to organizational security, as compromised developer environments can serve as gateways to broader systems.
Organizations should implement strict access controls and monitor for unusual activities within their development environments. Regular audits of installed extensions and software can help mitigate risks associated with malicious downloads. Additionally, educating developers about the potential threats posed by malware like Evelyn Stealer can foster a culture of security awareness.
As the landscape of cyber threats evolves, the rise of new malware families, such as MonetaStealer and SolyxImmortal, further emphasizes the importance of vigilance. These stealer malware variants also target sensitive user data and employ stealthy techniques to avoid detection. Organizations must remain proactive in their cybersecurity strategies to defend against these emerging threats.
Key Takeaways
- Review and limit the use of third-party VS Code extensions to those from trusted sources.
- Regularly audit installed software and extensions for any unauthorized or suspicious items.
- Implement strong access controls and monitor developer environments for unusual activities.
- Educate team members about the risks associated with malware targeting developer tools.
- Consider using endpoint protection solutions that can detect and respond to malware threats.
Key Terms & Concepts
- Evelyn Stealer: In this article, Evelyn Stealer refers to a malware campaign targeting software developers to exfiltrate sensitive information.
- Visual Studio Code (VS Code): VS Code is a popular code editor developed by Microsoft, often used by software developers for building applications.
- DLL: A DLL, or Dynamic Link Library, is a file that contains code and data that can be used by multiple programs simultaneously.
- PowerShell: PowerShell is a task automation framework from Microsoft, consisting of a command-line shell and associated scripting language.
- Stealer Malware: Stealer malware is designed to collect sensitive information from infected systems, such as credentials and personal data.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.