evoworld.io stealler - lastest version was reported 31-08-2026 for Malware
script collects and exfiltrates highly sensitive browser and account data, including:
Login credentials
PHPSESSID/session identifiers
All accessible cookies
localStorage and sessionStorage
User account data and account level
Friends/user-related data
IP address
Browser User-Agent
Current URL
Time zone, language, and network information
Other data exposed through the site's JavaScript variables
The collected account data is uploaded to a hardcoded GitHub repository using a hardcoded GitHub Personal Access Token. The script creates timestamped files containing the victim's data.
The script also implements a keylogger by recording keyboard input across the webpage. It periodically captures screenshots of the entire webpage using html2canvas and uploads them to a Discord webhook every 30 seconds. It continuously updates the same Discord message with the latest screenshot and keylogger data.
evoa ggsBị cấm (the reported user) has made:
This report has been upheld by a moderator.
