Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories
Malware Activity
Summary
Hide ▲
Show ▼
Rapuncel is an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to impersonate software brands, including LastPass, and lure people searching for LastPass Authenticator or similar software. The delivery chain drops a ZIP with vsdbg.exe and vsdbg.dll, then loads the Microsoft Windows Hardware Compatibility Publisher-signed Alinubx.sys driver to kill antivirus and EDR before the stealer runs. Researchers at LastPass and Delphos Labs said the fake page at github.com/LastPass-Authenticator also led to collection of browser passwords, Windows Credential Manager data, cryptocurrency wallet files, and Discord, Steam, and Telegram sessions. LastPass said its own systems, services, and customer vaults were untouched.
Related Happenings
SEO-optimized GitHub software-lure campaign pushing Rapuncel infostealer
Campaign
H score36
First: 18.09.2026 18:19
Last: 18.09.2026 18:19
Sources 1
How related:
The lure is a fake GitHub page (github.com/LastPass-Authenticator) that ranks in search results for terms like "LastPass Authenticator download" and looks like a real LastPass product page.
About this happening:
An ongoing SEO-optimized GitHub campaign is impersonating LastPass and at least 39 other companies to lure people searching for LastPass Authenticator and other do...
SEO-optimized GitHub software-lure campaign pushing Rapuncel infostealer
CampaignHow related: The lure is a fake GitHub page (github.com/LastPass-Authenticator) that ranks in search results for terms like "LastPass Authenticator download" and looks like a real LastPass product page.
About this happening: An ongoing SEO-optimized GitHub campaign is impersonating LastPass and at least 39 other companies to lure people searching for LastPass Authenticator and other do...
Shai-Hulud worm spread across internal repositories after AI assistant hijack
Malware Activity
H score12
First: 16.09.2026 16:37
Last: 16.09.2026 16:37
Sources 1
About this happening:
The Shai-Hulud worm spread across about 100 internal code repositories, exposing repository secrets and source code after an AI coding-assistant session was hi...
Shai-Hulud worm spread across internal repositories after AI assistant hijack
Malware ActivityAbout this happening: The Shai-Hulud worm spread across about 100 internal code repositories, exposing repository secrets and source code after an AI coding-assistant session was hi...
MayaBot malware activity in BengalSEO
Malware Activity
H score10
First: 08.09.2026 11:43
Last: 08.09.2026 11:43
Sources 1
About this happening:
The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, incr...
MayaBot malware activity in BengalSEO
Malware ActivityAbout this happening: The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, incr...
SynkLoader Microsoft Teams help-desk phishing campaign
Campaign
H score35
First: 21.08.2026 21:01
Last: 21.08.2026 21:01
Sources 1
About this happening:
The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open...
SynkLoader Microsoft Teams help-desk phishing campaign
CampaignAbout this happening: The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open...
StubMaker Windows information stealer delivered via RubyGems
Malware Activity
H score30
First: 18.08.2026 14:40
Last: 18.08.2026 14:40
Sources 1
About this happening:
The StubMaker malware activity is distributing a Windows information stealer through typosquatted RubyGems installs, putting browser credentials and crypto-walle...
StubMaker Windows information stealer delivered via RubyGems
Malware ActivityAbout this happening: The StubMaker malware activity is distributing a Windows information stealer through typosquatted RubyGems installs, putting browser credentials and crypto-walle...
Timeline
-
21.09.2026 20:31 1 articles · 3h ago
Fake GitHub LastPass Authenticator installer loads Microsoft-signed driver to disable security tools
Technical Analysis UpdateA fake GitHub page for github.com/LastPass-Authenticator delivered a ZIP containing vsdbg.exe and vsdbg.dll, then launched a Microsoft Windows Hardware Compatibility Publisher-signed Alinubx.sys kernel driver that terminated antivirus and other security processes before the stealer collected browser passwords, Windows Credential Manager data, cryptocurrency wallet files, and Discord, Steam, and Telegram sessions.
Show sources
- Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR — thehackernews.com — 21.09.2026 20:31
-
18.09.2026 18:19 2 articles · 3d ago
LastPass and Delphos Labs uncover Rapuncel campaign on fake GitHub repositories
Initial DisclosureLastPass and Delphos Labs uncovered an ongoing malware campaign that uses SEO-optimized GitHub repositories to impersonate software brands, including LastPass, and lure people searching for LastPass Authenticator or other popular software into fake repos that distribute Rapuncel, a previously undocumented infostealer, together with a Microsoft-signed kernel driver that can terminate 145 antivirus and EDR products.
Show sources
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer — www.bleepingcomputer.com — 18.09.2026 18:19
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer — www.bleepingcomputer.com — 18.09.2026 18:19