SEO-optimized GitHub software-lure campaign pushing Rapuncel infostealer
Campaign
Summary
Hide ▲
Show ▼
An ongoing SEO-optimized GitHub campaign is impersonating LastPass and at least 39 other companies to lure people searching for LastPass Authenticator and other downloads into fake repositories. The chain uses a fake GitHub page, oversized ZIP archives, a renamed vsdbg.exe loader, and a malicious DLL to sideload Rapuncel and the Alinubx.sys kernel driver. The driver is disguised as nvfsflt64.sys, registers as NvFsFilter, and can terminate 145 antivirus and EDR products before the stealer pulls browser credentials, wallet data, session credentials, Windows Credential Manager contents, and other files, then exfiltrates them to 2.26.126[.]50. LastPass said its own systems, services, and customer vaults were untouched.
Related Happenings
Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories
Malware Activity
H score26
First: 18.09.2026 18:19
Last: 18.09.2026 18:19
Sources 1
How related:
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.
About this happening:
Rapuncel is an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to impersonate software brands, including LastPass, and lure people search...
Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories
Malware ActivityHow related: A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.
About this happening: Rapuncel is an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to impersonate software brands, including LastPass, and lure people search...
Latest development: 21.09.2026 20:31
A fake GitHub page for github.com/LastPass-Authenticator delivered a ZIP containing vsdbg.exe and vsdbg.dll, then launched a Microsoft Windows Hardware Compatibility Publisher-signed Alinubx.sys kernel driver that terminated antivirus and other security processes before the stealer collected browser passwords, Windows Credential Manager data, cryptocurrency wallet files, and Discord, Steam, and Telegram sessions.
MayaBot malware activity in BengalSEO
Malware Activity
H score10
First: 08.09.2026 11:43
Last: 08.09.2026 11:43
Sources 1
About this happening:
The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, incr...
MayaBot malware activity in BengalSEO
Malware ActivityAbout this happening: The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, incr...
FakeAgent Bing malvertising campaign pushing fake Claude installer
Campaign
H score25
First: 23.07.2026 22:48
Last: 23.07.2026 22:48
Sources 1
About this happening:
The FakeAgent campaign used Bing search ads and a malicious Claude Artifact on Claude.ai to push a fake Claude desktop app installer that delivered SectopRAT...
FakeAgent Bing malvertising campaign pushing fake Claude installer
CampaignAbout this happening: The FakeAgent campaign used Bing search ads and a malicious Claude Artifact on Claude.ai to push a fake Claude desktop app installer that delivered SectopRAT...
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware Activity
H score30
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware ActivityAbout this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
Lurking Lizard trojanized 7-Zip installer campaign
Campaign
H score84
First: 09.07.2026 07:01
Last: 09.07.2026 07:01
Sources 1
About this happening:
A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
Lurking Lizard trojanized 7-Zip installer campaign
CampaignAbout this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
Timeline
-
18.09.2026 18:19 3 articles · 3d ago
SEO-optimized GitHub repos impersonate software brands to push Rapuncel
Initial DisclosureLastPass and Delphos Labs identified an ongoing malware campaign that uses SEO-optimized GitHub repositories to impersonate LastPass and at least 39 other companies, steering people who search for LastPass Authenticator or other popular software into fake repos. The download flow redirects victims to payload-delivery servers that serve ZIP archives, a renamed copy of Microsoft Visual Studio CoreCLR Debugger, 'vsdbg.exe,' and a malicious DLL that sideloads Rapuncel and the Alinubx.sys kernel driver. The driver is disguised as an NVIDIA component named 'nvfsflt64.sys,' registers as the NvFsFilter service, and can terminate 145 antivirus and endpoint detection and response (EDR) products, while Rapuncel steals browser credentials, cryptocurrency wallet data, session credentials, Windows Credential Manager contents, matching documents, screenshots, and system information before exfiltrating the data to '2.26.126[.]50' and persisting via a Windows service.
Show sources
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer — www.bleepingcomputer.com — 18.09.2026 18:19
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer — www.bleepingcomputer.com — 18.09.2026 18:19
- Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR — thehackernews.com — 21.09.2026 20:31