Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Fake LastPass Authenticator GitHub Repos Distribute Rapuncel Infostealer and Signed Kernel Driver

Threat actors have published SEO‑optimized GitHub repositories that masquerade as LastPass Authenticator and other software, delivering the Rapuncel infostealer and a Microsoft‑signed kernel driver that disables hundreds of security products. The campaign underscores the importance of third‑party software supply‑chain verification for audit readiness.

LiveThreat™ Intelligence · 📅 September 19, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

Fake LastPass Authenticator GitHub Repos Distribute New Rapuncel Infostealer

What Happened — A threat‑actor network has created SEO‑optimized GitHub repositories that masquerade as the LastPass Authenticator app and dozens of other legitimate software. The repos host a previously undocumented infostealer (named Rapuncel) and a Microsoft‑signed kernel driver that can terminate 145 antivirus/EDR products, allowing the payload to harvest credentials, wallet files, screenshots, and other sensitive data.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous third‑party software supply‑chain monitoring and verification of code authenticity.
  • Highlights gaps in endpoint protection when malicious drivers are signed and can bypass protected‑process mechanisms.
  • Provides a concrete example of a control objective—vendor/third‑party risk oversight—that, when satisfied, supplies evidence for multiple frameworks (e.g., NIST CSF, ISO 27001).

Who Is Affected – Users of password‑manager applications, cryptocurrency wallet holders, and any organization whose employees download software from public code repositories (technology, finance, media, etc.).

Recommended Actions

  • Enforce a policy that only approved, digitally‑signed binaries from verified vendor channels may be installed.
  • Deploy continuous monitoring of endpoint driver loads and maintain an up‑to‑date software bill of materials (SBOM).
  • Integrate automated alerts for newly published repositories that claim to be official versions of critical tools.

Technical Notes – The attack chain starts with a search for “LastPass Authenticator,” leading to a fake GitHub page. A ZIP archive (inflated to ~148 MB) contains a renamed vsdbg.exe that sideloads a malicious DLL and drops the Alinubx.sys driver (masquerading as nvfsflt64.sys). The driver uses kernel‑mode calls to terminate listed AV/EDR processes, evading Protected Process Light. The infostealer then extracts credentials from browsers, crypto wallets, Windows Credential Manager, and files matching password‑related patterns. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →