discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Fake LastPass Authenticator GitHub Repos Push New Rapuncel Infostealer

GitHub repositories impersonate LastPass and other firms to deliver malware, including a previously undocumented infostealer called Rapuncel.

By Bill Toulas·Sep 18·bleepingcomputer.com·2 min read

Intelligence analysis by Qwen 2.5 (3B)

Fake LastPass Authenticator GitHub Repos Push New Rapuncel Infostealer
Image: bleepingcomputer.com

Security researchers uncover a malware campaign using fake GitHub repositories to impersonate LastPass and other firms, delivering a previously undocumented infostealer called Rapuncel.

Why it matters

This campaign highlights the risks of using unverified GitHub repositories, potentially exposing users to malware.

Bad guys tricked people into downloading fake software from GitHub. The fake software is actually a sneaky program that steals passwords and other important stuff from your computer. It's like a trick to get your personal information.

Analysis

Attack Chain Overview

Fake GitHub Repositories

The attack begins when users search for LastPass Authenticator or other popular software and follow links to fake GitHub repositories. These repositories are designed to mimic legitimate software firms.

Malware Delivery

Clicking download buttons in the fake repositories triggers a series of redirections, leading to payload delivery servers. Victims receive ZIP archives with inflated sizes to evade security scans.

Malware Components

The installer inside the archives is a copy of the legitimate Microsoft Visual Studio CoreCLR Debugger, renamed and configured to sideload a malicious DLL (vsdbg.dll). The installer deploys the Rapuncel infostealer and the Alinubx.sys kernel driver, which is used to disable antivirus software.

Malware Functionality

The Rapuncel infostealer steals data from infected devices, including credentials, cryptocurrency wallets, and system information. It bypasses Google's app-bound encryption protection on Chrome, Edge, and related browsers by injecting a helper DLL and invoking its own Elevation Service.

Persistence

The malware persists across reboots via a Windows service, and security tools that reactivate are killed again before the infostealer launches.

Implications

  • User Awareness: Users are advised to only download software from official websites and avoid dubious GitHub repositories.
  • Security Measures: Security tools should be updated and configured to detect and block malicious GitHub repositories and malware components.

Future Outlook

  • GitHub Repository Verification: Improved verification processes for GitHub repositories could help prevent similar attacks in the future.
  • User Education: Continued education on recognizing and avoiding malicious GitHub repositories is crucial for user protection.

Key points

  • Fake GitHub repositories impersonate popular software firms to deliver malware.
  • The malware steals passwords, cryptocurrency wallets, and other sensitive information.
  • Users are advised to only download software from official websites and avoid dubious GitHub repositories.
The Upside

Future improvements in GitHub's verification process could help stop these fake software downloads, keeping people safer.

The Downside

If users don't learn to be careful and only download software from official websites, they might still get tricked by these fake downloads.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymalwaregithubinfostealercybersecurity

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 18, 2026

Source

bleepingcomputer.com

Share

Topics

securitymalwaregithubinfostealercybersecurity

Related

More from this desk

Oct 8·bleepingcomputer.com

Maryland Man Found Guilty of Stealing $53 Million from Decentralized Crypto Exchange Uranium Finance

Maryland man convicted of hacking Uranium Finance, a decentralized crypto exchange, and stealing $53 million in cryptocurrency.

Oct 8·wired.com

The Man Behind a West Bank Telegram Channel Trying to Keep Palestinian Drivers Safe

A Telegram group helps Palestinian drivers navigate checkpoints in the West Bank, where popular navigation apps fail them.

Oct 8·thehackernews.com

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering a $10 million reward for information on Zhang Yu, a Chinese national charged in the 2021 HAFNIUM Microsoft Exchange Server attacks.

Oct 8·thehackernews.com

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The owner of MonsterCloud, Zohar Pinhasi, is accused of defrauding ransomware victims by secretly paying attackers for decryptors while claiming to use proprietary tools. He allegedly charged clients millions more than the ransoms paid.