Cybersecurity researchers have revealed details of a malicious campaign targeting software developers with a new information-stealing malware called Evelyn Stealer, which exploits Microsoft’s Visual Studio Code (VS Code). The malware is designed to extract sensitive information, including developer credentials and cryptocurrency-related data.
See also: Spring vulnerability allows commands to be executed on the user's PC

Compromised developer environments can also be used as access points to broader organizational systems, according to Trend Micro. The campaign specifically targets organizations with software development teams that rely on VS Code and third-party extensions, particularly those with access to production systems, cloud resources, or digital assets.
Details of the campaign were first documented by Koi Security last month, revealing three VS Code extensions – BigBlack.bitcoin-black, BigBlack.codo-ai , and BigBlack.mrbigblacktheme – that install a malicious DLL downloader (“Lightshot.dll”). This DLL launches a hidden PowerShell command to retrieve and execute a second payload stage (“runtime.exe”).
The executable decrypts and injects the main theft payload into a legitimate Windows process (“grpconv.exe”) directly into memory, allowing it to collect sensitive data and export it to a remote server (“server09.mentality[.]cloud”) via FTP in the form of a ZIP file. Information collected by the malware includes:
- Cryptocurrency wallets
- Saved Wi-Fi credentials
- Credentials and stored cookies from Google Chrome and Microsoft Edge
See also: MacSync Stealer bypasses Apple's malware protections

The malware implements protection measures to detect analytics and virtual environments and takes steps to terminate active browser processes to ensure a seamless data collection process and prevent interference when extracting cookies and credentials.
This is achieved by launching the browser via the command line with specific flags to minimize detection. The downloader creates a mutex object to ensure that only one instance of the malware can run at any given time, preventing multiple instances on a compromised computer.
The Evelyn Stealer campaign reflects the operational exploitation of attacks against developer communities, which are considered high-value targets in the software development ecosystem.
The disclosure coincides with the emergence of two new families of Python-based data theft malware, MonetaStealer and SolyxImmortal. MonetaStealer is capable of targeting Apple macOS systems for extensive data theft. SolyxImmortal leverages legitimate system APIs and widely available third-party libraries to extract sensitive user data and export it to attacker-controlled Discord webhooks.
See also: Researchers discover malicious VS Code, Go, npm and Rust packages

Its design emphasizes stealth, reliability, and long-term access over rapid execution or destructive behavior. By operating entirely in user space and relying on trusted platforms for command and control, the malware reduces the likelihood of immediate detection while maintaining constant visibility into user activity.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
