Attackers have harnessed a malicious Visual Studio Code extension to deliver the multi-stage Evelyn information-stealing malware, reports Cyber Security News.Installation of the trojanized VS Code add-on prompts the covert deployment of a counterfeit Lightshot.dll component, which when executed by LightShot.exe as users capture screenshots, launches a concealed PowerShell command that retrieves and runs a second-stage file, according to Trend Micro researchers. Apart from compromising browser passwords, cryptocurrency wallets, messaging sessions, cookies, VPN profiles, Wi-Fi keys, and other files, Evelyn Stealer also pilfers detailed system information to an attacker-controlled FTP server.Researchers warned that the compromise of a lone developer laptop could result in the exposure of data, which could be weaponized to facilitate a sweeping network breach. Such findings come amid the increasingly prevalent exploitation of VS Code as an attacker platform.
Malware, Threat Intelligence, Data Security
Illicit VS Code extension delivers multi-stage Evelyn infostealer
(Credit: Alina – stock.adobe.com)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
