www.punto-informatico.it Malicious LastPass Repositories Distribute Rapuncel Infostealer via GitHub
Article Content
- •Fake LastPass repositories on GitHub distribute the Rapuncel infostealer.
- •Malware targets credentials from over 25 browsers and 30 crypto wallets.
- •A signed kernel driver can disable security processes, complicating detection.
A campaign impersonating LastPass has been identified, distributing the Rapuncel infostealer through fake GitHub repositories. Users searching for 'LastPass Authenticator download' are misled into downloading malicious software that masquerades as legitimate. The malware is capable of stealing sensitive information, including credentials from over 25 browsers and data from more than 30 cryptocurrency wallets. A signed kernel driver, disguised as an NVIDIA file, can terminate security processes, making detection difficult. The operation involved fraudulent organizations mimicking LastPass and other brands, using SEO tactics to appear at the top of search results. The malicious package can evade antivirus detection and is designed to maintain persistence on infected systems. LastPass and Delphos Labs have confirmed the findings and are working to mitigate the threat.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track BoryptGrab and LastPass in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Rapuncel Infostealer Campaign Targets Users via Fake LastPass GitHub Repositories A malware campaign named Rapuncel is impersonating LastPass and other software brands to steal user credentials. Discovered by LastPass and Delphos Labs, the campaign utilizes fake GitHub repositories to lure victims into downloading malicious software. The attack begins with users searching for LastPass…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…