Skip to main content

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

0
High
Malwaremalware
Published: 09/18/2026 (09/18/2026, 15:19:06 UTC)
Source: Bleeping Computer

Description

A malware campaign uses fake GitHub repositories impersonating LastPass Authenticator and other software brands to distribute the Rapuncel infostealer. The campaign delivers a Microsoft-signed kernel driver that disables 145 antivirus and EDR products, allowing the infostealer to harvest credentials, cryptocurrency wallet data, session tokens, and sensitive documents. The driver bypasses common protections by operating in kernel mode and is currently not blocked by Microsoft. The malware persists via a Windows service, re-killing security tools on reboot.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 15:31:56 UTC

Technical Analysis

This ongoing malware campaign leverages SEO-optimized fake GitHub repositories impersonating LastPass Authenticator and at least 39 other companies to distribute the previously undocumented Rapuncel infostealer. Victims searching for legitimate software are redirected to malicious repositories that deliver ZIP archives containing a renamed Microsoft Visual Studio CoreCLR Debugger executable configured to sideload a malicious DLL. This DLL installs the Rapuncel infostealer and a Microsoft-signed kernel driver (Alinubx.sys) disguised as an NVIDIA component. The driver terminates 145 known antivirus and EDR processes by opening them with kernel-level access, bypassing Protected Process Light protections. Rapuncel steals credentials from 25 web browsers, 30 cryptocurrency wallets, session tokens from Discord, Steam, and Telegram, Windows Credential Manager data, sensitive documents, screenshots, and detailed system information. It uploads stolen data to an external server and persists across reboots by reinstalling itself and disabling security software again. The driver also contains additional stealth and manipulation capabilities not activated in this campaign. Researchers assess Rapuncel as a variant of BoryptGrab with a loader built using the Cruciferra PUROSANGUE crypter.

Potential Impact

The campaign enables attackers to disable a wide range of antivirus and endpoint detection and response products, effectively neutralizing security defenses on infected systems. This allows the Rapuncel infostealer to exfiltrate sensitive credentials, cryptocurrency wallet data, session tokens, and confidential documents, potentially leading to account compromise, financial theft, and data breaches. Persistence mechanisms ensure continued infection and repeated disabling of security tools after system reboots.

Defensive Guidance

Users should avoid downloading software from unofficial or suspicious GitHub repositories and be cautious of promoted search results that may lead to malicious sites. There is no vendor patch available for the malicious driver or infostealer; mitigation relies on user vigilance and blocking access to known malicious domains and repositories. Security teams should monitor for the presence of the Alinubx.sys driver and the Rapuncel infostealer, though detection may be challenging due to the driver's kernel-level capabilities and Microsoft signature. Since the driver is not currently on Microsoft's vulnerable driver blocklist, organizations should watch for updates from Microsoft regarding blocking this driver. No official fix or patch is currently available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.83,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/","fetched":true,"fetchedAt":"2026-09-18T15:31:49.824Z","wordCount":841}

Threat ID: 6aad596555bf5e2cf52e3735

Added to database: 09/18/2026, 15:31:49 UTC

Last enriched: 09/18/2026, 15:31:56 UTC

Last updated: 09/18/2026, 22:31:34 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses