Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Anduril has invented a novel drone flying contest where work is the prize

Bluesky previews 2026 roadmap: Discover feed, real-time features, and more improvements

Anthropic and OpenAI CEOs condemn ICE violence, praise Trump

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Evelyn Stealer malware exploits VS Code extension to steal developer credentials and cryptography
Identity

Evelyn Stealer malware exploits VS Code extension to steal developer credentials and cryptography

userBy userJanuary 20, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananJanuary 20, 2026Cloud security / developer security

Cybersecurity researchers have revealed details of a malware campaign that targets software developers with a new information theft tool called Evelyn Stealer, armed with the Microsoft Visual Studio Code (VS Code) extension ecosystem.

“This malware is designed to exfiltrate sensitive information such as developer credentials and cryptocurrency-related data. A compromised developer environment can also be exploited as an access point to broader organizational systems,” Trend Micro said in an analysis published on Monday.

The effort aims to single out organizations with software development teams that rely on VS Code and third-party extensions, as well as those with access to production systems, cloud resources, or digital assets, it added.

Notably, details of the campaign were first documented by Koi Security last month, when details of three VS Code extensions were revealed: BigBlack.bitcoin-black, BigBlack.codo-ai, and BigBlack.mrbigblacktheme. The extension ultimately dropped a malicious downloader DLL (‘Lightshot.dll’) that launched a hidden PowerShell command to fetch and execute the second stage payload (‘runtime.exe’).

cyber security

This executable is able to decrypt and inject the main stealer payload directly into a legitimate Windows process (‘grpconv.exe’) in memory and collect and exfiltrate sensitive data to a remote server (‘server09.mentality’).[.]cloud”) via FTP in the form of a ZIP file. Information collected by the malware includes:

Clipboard contents Installed apps Cryptocurrency wallets Running processes Desktop screenshots Saved Wi-Fi credentials System information Credentials and saved cookies from Google Chrome and Microsoft Edge

Additionally, we implement safeguards to detect analytical and virtual environments and take steps to terminate active browser processes to ensure a seamless data collection process and prevent potential interference when attempting to extract cookies or credentials.

This is achieved by setting the following flags for detection and forensic tracing and launching the browser via command line:

–headless=new, run in headless mode –disable-gpu, prevent GPU acceleration –no-sandbox, disable browser security sandbox –disable-extensions, prevent interference from legitimate security extensions –disable-logging, disable browser log generation –silent-launch, suppress launch notifications –no-first-run, bypass initial configuration dialog –disable-popup-blocking, allow malicious content to run –window-position=-10000,-10000, position window off-screen –window-size=1,1, minimize window to 1×1 pixels

cyber security

” [DLL] “The downloader creates a mutually exclusive (mutex) object to ensure that only one instance of the malware is running at any given time and prevents multiple instances of the malware from running on a compromised host. The Evelyn Stealer campaign reflects the operationalization of attacks against the developer community, which is considered a high-value target given its important role in the software development ecosystem,” Trend Micro said.

This disclosure coincides with the emergence of two new Python-based stealer malware families called MonetaStealer and SolyxImmortal, the former of which also has the ability to target Apple macOS systems and enable comprehensive data theft.

”[SolyxImmortal] It leverages legitimate system APIs and widely available third-party libraries to extract and leak sensitive user data to attacker-controlled Discord webhooks,” CYFIRMA said.

“Its design emphasizes stealth, reliability, and long-term access rather than rapid execution or destructive behavior. The malware operates entirely in user space and relies on a trusted platform for command and control, reducing the likelihood of immediate detection while maintaining persistent visibility into user activity.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCloudflare fixes ACME validation bug, allows WAF bypass to origin server
Next Article The hidden risks of orphaned accounts
user
  • Website

Related Posts

WhatsApp deploys lockdown-style security mode to protect targeted users from spyware

January 27, 2026

Experts detect Pakistan-linked cyber attack targeting Indian government agencies

January 27, 2026

ClickFix attack spreads using fake CAPTCHAs, Microsoft Scripts, and trusted web services

January 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Anduril has invented a novel drone flying contest where work is the prize

Bluesky previews 2026 roadmap: Discover feed, real-time features, and more improvements

Anthropic and OpenAI CEOs condemn ICE violence, praise Trump

Amid President Trump’s attacks and weaponized sanctions, European countries seek to reduce dependence on U.S. technology

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.