Fake LastPass Authenticator GitHub Repos Push New Rapuncel Infostealer
GitHub repositories impersonate LastPass and other firms to deliver malware, including a previously undocumented infostealer called Rapuncel.
Intelligence analysis by Qwen 2.5 (3B)

Security researchers uncover a malware campaign using fake GitHub repositories to impersonate LastPass and other firms, delivering a previously undocumented infostealer called Rapuncel.
Bad guys tricked people into downloading fake software from GitHub. The fake software is actually a sneaky program that steals passwords and other important stuff from your computer. It's like a trick to get your personal information.
Analysis
Attack Chain Overview
Fake GitHub Repositories
The attack begins when users search for LastPass Authenticator or other popular software and follow links to fake GitHub repositories. These repositories are designed to mimic legitimate software firms.
Malware Delivery
Clicking download buttons in the fake repositories triggers a series of redirections, leading to payload delivery servers. Victims receive ZIP archives with inflated sizes to evade security scans.
Malware Components
The installer inside the archives is a copy of the legitimate Microsoft Visual Studio CoreCLR Debugger, renamed and configured to sideload a malicious DLL (vsdbg.dll). The installer deploys the Rapuncel infostealer and the Alinubx.sys kernel driver, which is used to disable antivirus software.
Malware Functionality
The Rapuncel infostealer steals data from infected devices, including credentials, cryptocurrency wallets, and system information. It bypasses Google's app-bound encryption protection on Chrome, Edge, and related browsers by injecting a helper DLL and invoking its own Elevation Service.
Persistence
The malware persists across reboots via a Windows service, and security tools that reactivate are killed again before the infostealer launches.
Implications
- User Awareness: Users are advised to only download software from official websites and avoid dubious GitHub repositories.
- Security Measures: Security tools should be updated and configured to detect and block malicious GitHub repositories and malware components.
Future Outlook
- GitHub Repository Verification: Improved verification processes for GitHub repositories could help prevent similar attacks in the future.
- User Education: Continued education on recognizing and avoiding malicious GitHub repositories is crucial for user protection.
Key points
- Fake GitHub repositories impersonate popular software firms to deliver malware.
- The malware steals passwords, cryptocurrency wallets, and other sensitive information.
- Users are advised to only download software from official websites and avoid dubious GitHub repositories.
Future improvements in GitHub's verification process could help stop these fake software downloads, keeping people safer.
If users don't learn to be careful and only download software from official websites, they might still get tricked by these fake downloads.



