MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-18 · via BleepingComputer

Malicious GitHub repos impersonating LastPass deliver novel data-stealing malware

Image via BleepingComputer
Image via BleepingComputer

A campaign discovered by LastPass and Delphos Labs uses search-optimized GitHub repositories posing as LastPass and dozens of other firms to distribute a previously unknown infostealer named Rapuncel. The attack chain also deploys a Microsoft-signed kernel driver that disables over 140 antivirus and endpoint detection products, bypassing protections like Protected Process Light. The installer abuses a legitimate Visual Studio debugger executable to sideload the malicious payload, with the driver disguised as an NVIDIA component.

Expanded Detail

The campaign leverages search-engine visibility, with malicious repositories appearing prominently in results for popular software downloads. LastPass and Delphos Labs identified at least 39 additional companies being impersonated, broadening the attack surface considerably. The signed kernel driver component is particularly concerning because it exploits kernel-mode access to bypass Protected Process Light, a security mechanism many endpoint products depend on for survival.

The Rapuncel stealer targets a wide range of sensitive data, including credentials from 25 browsers, 30 cryptocurrency wallets, and messaging platform sessions. It also scans for documents with password-related filenames and captures screenshots from all connected monitors. Researchers believe the malware is a variant of BoryptGrab, with its loader built using the Cruciferra PUROSANGUE crypter, suggesting an established criminal toolchain.

Context

This campaign could significantly undermine trust in open-source software distribution, as even technically savvy users may struggle to distinguish legitimate repositories from malicious impostors. The signed kernel driver element may also erode confidence in Microsoft's hardware certification process, potentially affecting enterprise security postures. Individuals and organizations relying on antivirus protection could face heightened risk if such drivers become more widely available to threat actors, though the current campaign appears targeted at credential and cryptocurrency theft rather than broader disruption.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer.” Browse more stories.