Bleepingcomputer Fake LastPass Downloads on GitHub Distribute Rapuncel Infostealer
Article Content
- •Fake GitHub repos impersonate LastPass and 39 other companies.
- •The Rapuncel infostealer collects sensitive data from browsers and wallets.
- •A Microsoft-signed kernel driver disables antivirus protections.
A malware campaign impersonating LastPass on GitHub has been uncovered, distributing an information stealer named Rapuncel. The campaign, identified by LastPass and Delphos Labs, uses fake GitHub repositories to lure users searching for LastPass Authenticator downloads. Victims are redirected to malicious download pages where they receive ZIP files containing a disguised installer that sideloads a malicious DLL. This installer deploys a kernel driver, Alinubx.sys, which can disable 145 antivirus and EDR products. The Rapuncel infostealer collects sensitive data including browser credentials, cryptocurrency wallet information, and session tokens from various applications. The malware also bypasses app-bound encryption in Chrome and Edge. LastPass confirmed that their systems were not compromised, and the attack was first detected on August 13, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track BoryptGrab and Nvidia in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…