Fake LastPass GitHub Drops Rapuncel Stealer

Security Affairs · High sophistication
Last updated September 23, 2026

Attackers impersonated LastPass on GitHub and tricked people searching for the “LastPass Authenticator download” into installing a fake installer. The infection chain used a Microsoft-signed driver to disable many security tools, then deployed an infostealer that stole passwords, crypto wallets, and messaging session data. LastPass says it was not breached, attackers only abused its brand and user trust.

Key findings

  • Attackers created a fake GitHub organization impersonating LastPass, using real branding and fake trust badges to convince users to download a malicious “authenticator.”
  • The campaign used multi-stage redirection (including GitHub Pages and a server behind Cloudflare) to deliver malware and rotate infrastructure.
  • A Microsoft-signed kernel driver was used to disable “145 different antivirus and EDR products,” enabling infostealer deployment.
  • LastPass states it was not breached; the lure was distributed outside official LastPass channels and GitHub is not an official distribution channel.
  • The infostealer (tracked by LastPass as “Rapuncel”) targeted browser passwords, crypto wallet files, tokens/sessions (e.g., Discord/Steam), Telegram data, Windows Credential Manager, and screenshots.

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Security, Helpdesk, Procurement.
  • Affected industries: Software and SaaS, Technology, Any organization whose employees download tools from GitHub.
  • Attack channels: website.
  • Impersonated: LastPass, LastPass (and other spoofed brands).

Awareness takeaways

  • Treat “official-looking” GitHub pages as untrusted unless the vendor explicitly lists GitHub as an approved download channel.
  • Don’t rely on trust badges or “clean scan” claims (including VirusTotal screenshots) as proof a download is safe, verify the source and distribution path.
  • A valid Microsoft signature does not automatically mean a driver/file is safe; follow approved software install processes and report unexpected installers immediately.
  • If you downloaded security tools/authenticators from random links recently, escalate quickly for review, these campaigns are actively maintained and can steal credentials and sessions.

Red flags to watch for

  • Repository/org is on GitHub even though the vendor does not distribute there
  • Trust badges like “VirusTotal Approved” presented as proof of safety
  • Download flow includes unexpected redirects or broken/404-looking pages
  • Multiple unexpected redirects after clicking download
  • Intermediate pages look like error pages (e.g., “broken 404”) but still redirect
  • Recently changed download endpoints/hosts over short time windows
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You Google “LastPass Authenticator download” and click a top result on GitHub that looks totally official. But it’s fake. Someone impersonated LastPass on GitHub, then used redirects and a Microsoft-signed driver to slip in the Rapuncel infostealer that drains browser passwords, crypto wallets, and chat sessions. Here’s the trap: GitHub is not a LastPass distribution channel. Those “VirusTotal Approved” badges were meaningless, and that Microsoft signature only proved the driver passed a pipeline, not that it was safe. Your move: if you ever downloaded an authenticator or security tool from a GitHub link, stop and report it to IT now so they can check for Rapuncel.

Categories

Similar attacks

Fake LastPass App on GitHub Drops Rapuncel Stealer

Fake LastPass App on GitHub Drops Rapuncel Stealer

Attackers used fake “LastPass Authenticator” and fake macOS LastPass pages on GitHub to trick people into downloading a malicious installer. The campaign relied on SEO so the fraudulent GitHub page appeared near the top of search results, then redirected victims through multiple pages to a download…

September 21, 2026
Fake GTA 6 Demo Sites Push Password Stealer

Fake GTA 6 Demo Sites Push Password Stealer

Attackers are exploiting GTA 6 hype by creating convincing fake Rockstar-branded “demo” websites that appear in Google search results. The sites use “Play Now”/“Official Download” lures to trick people into downloading a small Windows executable that installs Vidar infostealer and steals saved…

August 24, 2026
Fake LastPass Download on GitHub Drops Stealer

Fake LastPass Download on GitHub Drops Stealer

Researchers found attackers impersonating LastPass with a fake GitHub “LastPass Authenticator” download page that tricks people into downloading a large ZIP and running a fake installer. The installer uses a Microsoft-signed Windows driver to shut down antivirus/EDR tools, then runs a password…

September 21, 2026
Fake Downloads and Extensions Steal Sessions Fast

Fake Downloads and Extensions Steal Sessions Fast

The article highlights real, ongoing campaigns where attackers trick people into installing malware via fake software-download websites and a disguised browser extension. These lures are used to steal credentials, browser cookies, and authenticated sessions, letting attackers take over accounts…

September 11, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Fake Free COD Points Scam Steals Logins and 2FA

Fake Free COD Points Scam Steals Logins and 2FA

A real phishing campaign targeted Call of Duty Mobile players by promising free in-game currency. Victims were tricked into entering their email and password, then providing a 2FA code on a follow-up page, enabling attackers to take over accounts.

August 2, 2026