bleeping-computer · Crawled Sep 18, 2026
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
7 IoCs
Read original article ↗
AI Summary
A malware campaign is distributing a new information stealer named Rapuncel through SEO-optimized fake GitHub repositories impersonating LastPass and 39 other software brands. The attack delivers the Rapuncel infostealer alongside a Microsoft-signed kernel driver, Alinubx.sys, which disables 145 antivirus and EDR products by exploiting kernel-level access. The malware steals credentials from browsers, cryptocurrency wallets, Discord, Steam, Telegram, Windows Credential Manager, and specific documents, while also capturing screenshots and system information, exfiltrating data to a C2 server via raw TCP.
AI-extracted · verify before operational use