Fake LastPass App on GitHub Drops Rapuncel Stealer

Security Week Feed · Medium sophistication
Last updated September 22, 2026

Attackers used fake “LastPass Authenticator” and fake macOS LastPass pages on GitHub to trick people into downloading a malicious installer. The campaign relied on SEO so the fraudulent GitHub page appeared near the top of search results, then redirected victims through multiple pages to a download that installed an infostealer (“Rapuncel”) and a kernel driver meant to disable security tools.

How the attack worked

Attackers built a fake LastPass Authenticator page and hosted it on GitHub, along with fake macOS LastPass pages. Rather than relying on email, the campaign leaned on SEO optimization so the fraudulent GitHub page appeared among the top search results for users looking for the legitimate application. Anyone searching for LastPass Authenticator could land directly on the attacker's page without ever visiting an email link.

Victims who clicked through were routed through a hidden chain of multiple GitHub pages and a Cloudflare-fronted server before reaching a final download page. That page served an archive containing a fake installer, a malicious file, and junk files meant to pad out the package and make it look more legitimate.

What the payload did

The installer itself was a renamed version of Microsoft's own debugging tool. When executed, it loaded a companion DLL containing the attacker's code. That code installed a Microsoft-attested kernel driver disguised as an NVIDIA component, which was used to terminate 145 different AV and EDR tools. Once security tooling was disabled, the Rapuncel infostealer ran, searching for passwords stored in browsers, crypto wallet files, and tokens or data from apps such as Discord, Steam, and Telegram, along with taking screenshots and profiling the infected system.

Why it succeeded

This attack succeeded by exploiting trust in search results rather than trust in a person or email. Users assume that a top search result for a well-known product name is legitimate, and GitHub's reputation as a developer platform likely made the hosting choice seem less suspicious than an unknown site. The multi-hop redirect chain also added distance between the initial search click and the final malicious download, making it harder for a casual user to notice anything was wrong before running the installer.

What to watch for

  • Software download pages hosted on GitHub repositories or pages instead of a vendor's official site or app store
  • Multiple redirects before reaching a final download page
  • Archives containing extra or unexplained "junk" files alongside an installer
  • Installers with names or behavior that don't match the expected vendor tool

Building resistance

Organizations and individuals should only install security or password tools from the vendor's official site or an official app store, and should not trust top search results by default. Treat GitHub-hosted "installers" for well-known products with suspicion, especially when they involve multiple redirects. IT and security teams can reinforce this by training all employees, including helpdesk staff, to recognize these patterns before running any downloaded installer.

Key findings

  • A fake LastPass Authenticator distributed via GitHub was used as a lure; LastPass states its internal systems were not compromised.
  • Attackers used SEO so the fraudulent GitHub page appeared in top search results for the legitimate app.
  • Victims were redirected through multiple GitHub pages and a Cloudflare-fronted server to a final download page.
  • The downloaded archive contained a fake installer (renamed Microsoft debugging tool) that loaded a malicious DLL.
  • The malware installed a Microsoft-attested kernel driver posing as an NVIDIA component to terminate 145 AV/EDR tools, then ran the “Rapuncel” infostealer.
  • Rapuncel searched for passwords in browsers, crypto wallet files, and tokens/data from apps like Discord, Steam, and Telegram, plus took screenshots and system profiling.

Who’s being targeted

  • Commonly targeted roles: All employees, IT support/helpdesk, Security team, Employees who download/install software.
  • Affected industries: Cross-industry (any organization whose users search for and install security/password tools), Consumers/end users.
  • Attack channels: website.
  • Impersonated: LastPass.

Red flags to watch for

  • Software download is hosted on GitHub pages/repositories instead of the vendor’s official site/app store
  • Multiple redirects before reaching the final download page
  • Downloaded archive contains extra “junk” files and a suspicious installer name/behavior
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers get a fake LastPass app to rank high in search results?

They used SEO optimization on a GitHub page hosting the fraudulent LastPass Authenticator so it appeared among the top results for users searching for the legitimate application.

What happened after a victim downloaded the fake installer?

The archive contained a fake installer, a malicious file, and junk files. When executed, the installer, a renamed version of Microsoft's own debugging tool, loaded a companion DLL containing the attacker's code, which installed a kernel driver to disable security tools before running the Rapuncel infostealer.

Was LastPass itself compromised?

No, LastPass states its internal systems were not compromised; the fake app was distributed independently via GitHub.

What did the Rapuncel infostealer target?

It searched for passwords in browsers, crypto wallet files, and tokens or data from apps like Discord, Steam, and Telegram, and also took screenshots and profiled the system.

Read the video transcript

You Google “LastPass Authenticator,” click a top GitHub result, install it… and quietly hand over your passwords and crypto. Attackers built a fake LastPass Authenticator on GitHub, boosted it with SEO, then bounced you through several GitHub pages and a Cloudflare-fronted site to a download that drops the Rapuncel infostealer. The archive you get has a fake installer, actually a renamed Microsoft debugging tool, that loads a hidden DLL, installs a kernel driver posing as NVIDIA, kills over a hundred security tools, then Rapuncel starts scraping browser passwords, wallets, Discord, Steam, Telegram, and screenshots. Here’s the move: if you’re installing LastPass or any big-name app, skip search results. Go straight to the vendor’s official site or your app store and download only from there.

Categories

Similar attacks

Fake LastPass Download on GitHub Drops Stealer

Fake LastPass Download on GitHub Drops Stealer

Researchers found attackers impersonating LastPass with a fake GitHub “LastPass Authenticator” download page that tricks people into downloading a large ZIP and running a fake installer. The installer uses a Microsoft-signed Windows driver to shut down antivirus/EDR tools, then runs a password…

September 21, 2026
Fake Free COD Points Scam Steals Logins and 2FA

Fake Free COD Points Scam Steals Logins and 2FA

A real phishing campaign targeted Call of Duty Mobile players by promising free in-game currency. Victims were tricked into entering their email and password, then providing a 2FA code on a follow-up page, enabling attackers to take over accounts.

August 2, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
ClickFix Lures Spread ChainScript RAT

ClickFix Lures Spread ChainScript RAT

Researchers describe real-world “ClickFix” social-engineering lures that trick people into installing malware by downloading fake apps (like Spotify/Zoom/Teams) or copying commands into Terminal. One campaign abused a compromised, verified HBO Max Reddit account to run malicious ads, while another…

September 21, 2026
Fake Downloads and Extensions Steal Sessions Fast

Fake Downloads and Extensions Steal Sessions Fast

The article highlights real, ongoing campaigns where attackers trick people into installing malware via fake software-download websites and a disguised browser extension. These lures are used to steal credentials, browser cookies, and authenticated sessions, letting attackers take over accounts…

September 11, 2026
BengalSEO Tricks Bing Users Into Malware & Scam Calls

BengalSEO Tricks Bing Users Into Malware & Scam Calls

Researchers uncovered a long-running “SEO poisoning” operation that manipulates Bing search results to push people onto fake support and activation pages. Victims are steered through a chain of redirects to either download a malware-laced ZIP (MayaBot) or be pressured into calling a fake…

September 8, 2026