Threats & Adversaries · Credential Theft

Fake LastPass Authenticator Repos Push Rapuncel

BleepingComputer reported an ongoing campaign using SEO-optimized GitHub repositories to impersonate LastPass Authenticator and deliver a new infostealer called Rapuncel. The lure is the repository itself: people searching GitHub for the app can be steered to a fake project that looks legitimate enough to download or run.

In plain terms, the attackers are gaming search results on a trusted code-hosting site, so the infection path starts where users expect to find safe software. That turns brand search into part of the delivery chain and gives the malware a cleaner trust signal than a random download page would have.

For teams, the exposure is not limited to LastPass branding. Any workflow that treats a top-ranked public repository as proof of authenticity can be steered the same way, and the result is credential theft from users who trusted the search result more than the code.

3 sources · 7h ago

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-21

Every edition of this story: Fake LastPass Authenticator Repos Push Rapuncel

More from today