evoworld.io stealler - lastest version was reported 31. 08. 2026 for Malware

The reporter said:

script collects and exfiltrates highly sensitive browser and account data, including:

Login credentials
PHPSESSID/session identifiers
All accessible cookies
localStorage and sessionStorage
User account data and account level
Friends/user-related data
IP address
Browser User-Agent
Current URL
Time zone, language, and network information
Other data exposed through the site's JavaScript variables

The collected account data is uploaded to a hardcoded GitHub repository using a hardcoded GitHub Personal Access Token. The script creates timestamped files containing the victim's data.

The script also implements a keylogger by recording keyboard input across the webpage. It periodically captures screenshots of the entire webpage using html2canvas and uploads them to a Discord webhook every 30 seconds. It continuously updates the same Discord message with the latest screenshot and keylogger data.

evoa ggsBanned (the reported user) has made:

This report has been upheld by a moderator.