bleeping-computer · Crawled Sep 18, 2026

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

7 IoCs
Read original article ↗

AI Summary

A malware campaign is distributing a new information stealer named Rapuncel through SEO-optimized fake GitHub repositories impersonating LastPass and 39 other software brands. The attack delivers the Rapuncel infostealer alongside a Microsoft-signed kernel driver, Alinubx.sys, which disables 145 antivirus and EDR products by exploiting kernel-level access. The malware steals credentials from browsers, cryptocurrency wallets, Discord, Steam, Telegram, Windows Credential Manager, and specific documents, while also capturing screenshots and system information, exfiltrating data to a C2 server via raw TCP.

AI-extracted · verify before operational use

Indicators of Compromise 7 extracted

Type Value Detail
Domain 2[.]26[.]126[.]50 Details →
IP 2[.]26[.]126[.]50 Details →
Filename vsdbg.exe Details →
Filename vsdbg.dll Details →
Filename Alinubx.sys Details →
Filename nvfsflt64.sys Details →
GitHub Repo LastPass Details →