Threats · 6h ago
BleepingComputer reported an ongoing campaign using SEO-optimized GitHub repositories to impersonate LastPass Authenticator and deliver a new infostealer called Rapuncel. The lure is the repository itself: people searching GitHub for the app can be steered to a fake project that looks legitimate enough to download or run.
In plain terms, the attackers are gaming search results on a trusted code-hosting site, so the infection path starts where users expect to find safe software. That turns brand search into part of the delivery chain and gives the malware a cleaner trust signal than a random download page would have.
For teams, the exposure is not limited to LastPass branding. Any workflow that treats a top-ranked public repository as proof of authenticity can be steered the same way, and the result is credential theft from users who trusted the search result more than the code.
3 sources covering this story
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer uses a signed kernel driver to kill security tools before a stealer collects passwords and wallet files.
Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer
The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware.
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
Part of the PlainSec briefing for 2026-09-21