Fake LastPass Authenticator Repos on GitHub Deliver New Rapuncel Infostealer

Campaign impersonates 40 companies, uses Microsoft-signed driver to disable antivirus

By LineZotpaper
Published
Read Time2 min
An ongoing malware campaign is using SEO-optimized fake GitHub repositories that impersonate LastPass and roughly 39 other companies to distribute a previously unknown information stealer called Rapuncel, alongside a Microsoft-signed kernel driver capable of disabling antivirus and endpoint detection tools, researchers reported.

Security researchers from LastPass and Delphos Labs have uncovered a malware campaign that lures victims through search engines to lookalike GitHub repositories offering legitimate software such as LastPass Authenticator. The campaign, active as of September 2026, delivers a new infostealer named Rapuncel and a kernel driver that can terminate 145 security products.

The attack chain begins when users search for popular software and click on fake repository links. Download buttons on these pages trigger a series of redirections before reaching payload-delivery servers, where victims receive ZIP archives inflated to up to 148MB to evade security scans, according to the researchers.

Inside the archive, the installer is a renamed copy of the legitimate Microsoft Visual Studio CoreCLR Debugger (vsdbg.exe), configured to sideload a malicious DLL (vsdbg.dll). The installer then deploys the Rapuncel infostealer and the Alinubx.sys kernel driver, disguised as an NVIDIA component named nvfsflt64.sys and registered as the NvFsFilter service.

The driver acts as an EDR killer, containing a hardcoded list of 145 antivirus and EDR processes it attempts to terminate. LastPass explained the driver bypasses user-mode access checks by calling ObOpenObjectWithPointer in kernel mode, defeating Protected Process Light (PPL) protections that many security products rely on. The driver is currently not on Microsoft's vulnerable drivers blocklist and is signed through Microsoft's Windows Hardware Compatibility Publisher chain. The researchers noted Alinubx.sys also has capabilities for file and registry hiding, DLL injection, driver and process interception, traffic manipulation, and port redirection, though these were not activated in this campaign.

Oncetargeted for termination, the Rapuncel infostealer exfiltrates data, including credentials from 25 web browsers, data from 30 cryptocurrency wallets, Discord/Steam/Telegram session credentials, Windows Credential Manager contents, and documents with names containing keywords like 'password,' 'seed,' 'wallet,' or 'recovery.' It also captures screenshots from every connected monitor and detailed system information. It bypasses Google's app-bound encryption on Chrome and Edge by injecting a helper DLL and invoking its own Elevation Service. Stolen data is compressed and uploaded to an external endpoint at 2.26.126[.]50 over raw TCP. The malware persists across reboots via a Windows service, so any reactivated security tools are killed again.

§

Analysis

Why

  • This campaign targets users seeking popular software, meaning anyone downloading a program like LastPass Authenticator from a search engine could be infected with credential-stealing malware.
  • The use of a Microsoft-signed driver highlights how attackers can abuse driver signing to disable security software, undermining trust in hardware-verified protection.
  • With a previously unknown infostealer and the ability to evade security scans, this campaign represents a significant supply-chain-style risk for individuals and enterprises.

Background

Infostealers are a common type of malware designed to harvest credentials and sensitive data from compromised machines. Attackers increasingly use SEO poisoning and fake software repositories to trick users. The use of kernel drivers, especially signed ones, to disable security protections has been a persistent challenge; attackers often seek to exploit test-signing or leaked signing certificates. Microsoft maintains a vulnerable driver blocklist to prevent such abuse, but this campaign's driver is not yet listed.

Key perspectives

  • Security researchers (LastPass and Delphos Labs): They provide detailed technical analysis, emphasizing the bypass of PPL protections and the need for organizations to block the identified driver and endpoint.
  • Users and system administrators: They are the primary targets, facing risks of credential theft and system compromise; they may need to avoid downloading software from unofficial GitHub repos and enforce application whitelisting.
  • Microsoft: The company has not commented publicly, but the driver's signature through the Windows Hardware Compatibility Publisher chain raises questions about signing practices and detection; the blocklist may need updating.

Watch

  • Monitor whether Microsoft adds Alinubx.sys to the vulnerable drivers blocklist following public disclosure.
  • Watch for reports of active infections or follow-up campaigns using the same infrastructure or driver.
  • Check security advisories from GitHub or search engines regarding takedowns of fake repositories to assess how quickly this can be contained.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.