Find notable cyber news and cases, enriched with sources, timelines, and signals.

SEO-optimized GitHub software-lure campaign pushing Rapuncel infostealer

Campaign
First reported
Last updated
Happening score
H score 36
2 unique sources, 2 articles

Summary

Hide ▲

An ongoing SEO-optimized GitHub campaign is impersonating LastPass and at least 39 other companies to lure people searching for LastPass Authenticator and other downloads into fake repositories. The chain uses a fake GitHub page, oversized ZIP archives, a renamed vsdbg.exe loader, and a malicious DLL to sideload Rapuncel and the Alinubx.sys kernel driver. The driver is disguised as nvfsflt64.sys, registers as NvFsFilter, and can terminate 145 antivirus and EDR products before the stealer pulls browser credentials, wallet data, session credentials, Windows Credential Manager contents, and other files, then exfiltrates them to 2.26.126[.]50. LastPass said its own systems, services, and customer vaults were untouched.

Related Happenings

Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories

Malware Activity
H score26 First: 18.09.2026 18:19 Last: 18.09.2026 18:19 Sources 1

How related: A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.

About this happening: Rapuncel is an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to impersonate software brands, including LastPass, and lure people search...

Latest development: 21.09.2026 20:31

A fake GitHub page for github.com/LastPass-Authenticator delivered a ZIP containing vsdbg.exe and vsdbg.dll, then launched a Microsoft Windows Hardware Compatibility Publisher-signed Alinubx.sys kernel driver that terminated antivirus and other security processes before the stealer collected browser passwords, Windows Credential Manager data, cryptocurrency wallet files, and Discord, Steam, and Telegram sessions.

MayaBot malware activity in BengalSEO

Malware Activity
H score10 First: 08.09.2026 11:43 Last: 08.09.2026 11:43 Sources 1

About this happening: The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, incr...

FakeAgent Bing malvertising campaign pushing fake Claude installer

Campaign
H score25 First: 23.07.2026 22:48 Last: 23.07.2026 22:48 Sources 1

About this happening: The FakeAgent campaign used Bing search ads and a malicious Claude Artifact on Claude.ai to push a fake Claude desktop app installer that delivered SectopRAT...

BoryptGrab infostealer variant delivered via fake GitHub repositories

Malware Activity
H score30 First: 14.07.2026 22:15 Last: 14.07.2026 22:15 Sources 1

About this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...

Lurking Lizard trojanized 7-Zip installer campaign

Campaign
H score84 First: 09.07.2026 07:01 Last: 09.07.2026 07:01 Sources 1

About this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...

Timeline

  1. 18.09.2026 18:19 3 articles · 3d ago

    SEO-optimized GitHub repos impersonate software brands to push Rapuncel

    Initial Disclosure

    LastPass and Delphos Labs identified an ongoing malware campaign that uses SEO-optimized GitHub repositories to impersonate LastPass and at least 39 other companies, steering people who search for LastPass Authenticator or other popular software into fake repos. The download flow redirects victims to payload-delivery servers that serve ZIP archives, a renamed copy of Microsoft Visual Studio CoreCLR Debugger, 'vsdbg.exe,' and a malicious DLL that sideloads Rapuncel and the Alinubx.sys kernel driver. The driver is disguised as an NVIDIA component named 'nvfsflt64.sys,' registers as the NvFsFilter service, and can terminate 145 antivirus and endpoint detection and response (EDR) products, while Rapuncel steals browser credentials, cryptocurrency wallet data, session credentials, Windows Credential Manager contents, matching documents, screenshots, and system information before exfiltrating the data to '2.26.126[.]50' and persisting via a Windows service.

    Show sources