Fake LastPass Authenticator GitHub Repos Distribute New Rapuncel Infostealer
What Happened — A threat‑actor network has created SEO‑optimized GitHub repositories that masquerade as the LastPass Authenticator app and dozens of other legitimate software. The repos host a previously undocumented infostealer (named Rapuncel) and a Microsoft‑signed kernel driver that can terminate 145 antivirus/EDR products, allowing the payload to harvest credentials, wallet files, screenshots, and other sensitive data.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous third‑party software supply‑chain monitoring and verification of code authenticity.
- Highlights gaps in endpoint protection when malicious drivers are signed and can bypass protected‑process mechanisms.
- Provides a concrete example of a control objective—vendor/third‑party risk oversight—that, when satisfied, supplies evidence for multiple frameworks (e.g., NIST CSF, ISO 27001).
Who Is Affected – Users of password‑manager applications, cryptocurrency wallet holders, and any organization whose employees download software from public code repositories (technology, finance, media, etc.).
Recommended Actions
- Enforce a policy that only approved, digitally‑signed binaries from verified vendor channels may be installed.
- Deploy continuous monitoring of endpoint driver loads and maintain an up‑to‑date software bill of materials (SBOM).
- Integrate automated alerts for newly published repositories that claim to be official versions of critical tools.
Technical Notes – The attack chain starts with a search for “LastPass Authenticator,” leading to a fake GitHub page. A ZIP archive (inflated to ~148 MB) contains a renamed vsdbg.exe that sideloads a malicious DLL and drops the Alinubx.sys driver (masquerading as nvfsflt64.sys). The driver uses kernel‑mode calls to terminate listed AV/EDR processes, evading Protected Process Light. The infostealer then extracts credentials from browsers, crypto wallets, Windows Credential Manager, and files matching password‑related patterns. Source: BleepingComputer