[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpmIsRJ5jh4jaAf4AqFXyfLEHfl_K5C-ruNzG21ftGkk":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"4f0e86ae-2425-422d-b821-910f8eedb764","Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer","fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer-a8f08a","An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]","A malware campaign is using SEO-optimized GitHub repositories to impersonate legitimate software companies, including LastPass, to distribute a new information stealer named Rapuncel. The campaign also delivers a kernel driver, disguised as an NVIDIA component, capable of disabling 145 antivirus and EDR products by exploiting kernel-mode access to terminate processes. The Rapuncel infostealer then collects credentials from browsers, cryptocurrency wallets, and system files, uploading the data to a remote server.","Fake GitHub repos impersonate software firms to distribute Rapuncel infostealer and an EDR killer.","Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer By Bill Toulas September 18, 2026 11:19 AM 0 An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. LastPass and Delphos Labs uncovered the campaign, which they report impersonates the password manager brand and at least 39 other companies. Alongside the Rapuncel infostealer, the repositories deliver a Microsoft-signed kernel driver that can disable 145 antivirus and endpoint detection and response (EDR) products. The attack chain begins when victims search for LastPass Authenticator or other popular software and follow links to fake GitHub repos. There, clicking download buttons triggers a series of redirections before reaching payload-delivery servers, where victims receive ZIP archives with their size inflated to up to 148MB to evade security scans. The installer inside the archives is a copy of the legitimate Microsoft Visual Studio CoreCLR Debugger, 'vsdbg.exe,' renamed and configured to sideload a malicious DLL (vsdbg.dll). The installer deploys the Rapuncel infostealer as well as the Alinubx.sys kernel driver, which is used to kill antivirus software. Malicious GitHub pageSource: LastPass The kernel driver is disguised as an NVIDIA component named 'nvfsflt64.sys' and registers as the NvFsFilter service. According to the researchers, the driver acts as an EDR killer that contains a hardcoded list of 145 antivirus and EDR processes that it aims to terminate. \"The driver calls ObOpenObjectByPointer with AccessMode=KernelMode, which bypasses the normal user-mode SeAccessCheck path at handle-open time,\" explains LastPass. \"It asks the kernel to open the process as kernel code, then kills it. That is why it can defeat Protected Process Light (PPL); the protection many security products rely on to survive an administrator.\" Currently, the driver is not in Microsoft's vulnerable drivers blocklist, and the one used in the campaign is signed through Microsoft's Windows Hardware Compatibility Publisher chain. The researchers noted that Alinubx.sys contains additional capabilities for file and registry hiding, DLL injection, driver and process interception, traffic manipulation, and port redirection, but do not appear to be activated in this campaign. The Rapuncel infostealer Once security software is terminated on the device, the Rapuncel infostealer begins stealing data from the infected device. The malware collects the following information: Credentials stored in 25 web browsers Data from 30 cryptocurrency wallets Discord, Steam, and Telegram session credentials Windows Credential Manager contents Documents with names containing \"password,\" \"seed,\" \"wallet,\" or \"recovery\" Screenshots from every connected monitor Detailed system information To bypass Google's app-bound encryption protection present on Chrome, Edge, and related browsers, Rapuncel injects a helper DLL into the app and invokes its own Elevation Service. The stolen information is compressed and uploaded to an external endpoint at '2.26.126[.]50' using an HTTP-formatted request sent over raw TCP. Rapuncel persists across reboots via a Windows service, so any security tools that reactivate are killed again before the infostealer launches. LastPass and Delphos Labs assessed with moderate confidence that Rapuncel is a variant of BoryptGrab, while they also found that its loader was built with the Cruciferra PUROSANGUE crypter. Users are recommended to only download software from official websites, avoid dubious GitHub repositories, and skip or block promoted results on Google Search. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: New Infinity Stealer malware grabs macOS data via ClickFix luresFake Roblox Xeno script launcher pushes infostealer, RAT malwareArch Linux disables AUR package adoption to stop malware floodMicrosoft warns of surge in ACR Stealer attacks on customersVoidStealer malware steals Chrome master key via debugger trick","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Ffake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F06\u002F23\u002Flastpass.jpg","2026-09-18T15:19:06+00:00","2026-09-18T16:00:37.749856+00:00",8,[18,21,24,26,28,30],{"name":19,"type":20},"LastPass Authenticator","product",{"name":22,"type":23},"LastPass","vendor",{"name":25,"type":20},"GitHub",{"name":27,"type":20},"Microsoft Visual Studio CoreCLR Debugger",{"name":29,"type":20},"vsdbg.exe",{"name":31,"type":20},"nvfsflt64.sys","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":32,"icon":34,"name":35,"slug":36},null,"Malware","malware",[38,43,48,50],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":49},{"id":32,"icon":34,"name":35,"slug":36},{"category":51},{"id":52,"icon":34,"name":53,"slug":54},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[56,60,63,66,69],{"type":57,"value":58,"context":59},"ip","2.26.126.50","C2 server IP address for Rapuncel infostealer",{"type":36,"value":61,"context":62},"Rapuncel","Name of the information stealer",{"type":36,"value":64,"context":65},"Alinubx.sys","Name of the kernel driver used to kill AV\u002FEDR",{"type":36,"value":67,"context":68},"BoryptGrab","Potential variant of Rapuncel infostealer",{"type":36,"value":70,"context":71},"Cruciferra PUROSANGUE","Crypter used for the Rapuncel loader"]