Security researchers from LastPass and Delphos Labs have uncovered a malware campaign that lures victims through search engines to lookalike GitHub repositories offering legitimate software such as LastPass Authenticator. The campaign, active as of September 2026, delivers a new infostealer named Rapuncel and a kernel driver that can terminate 145 security products.
The attack chain begins when users search for popular software and click on fake repository links. Download buttons on these pages trigger a series of redirections before reaching payload-delivery servers, where victims receive ZIP archives inflated to up to 148MB to evade security scans, according to the researchers.
Inside the archive, the installer is a renamed copy of the legitimate Microsoft Visual Studio CoreCLR Debugger (vsdbg.exe), configured to sideload a malicious DLL (vsdbg.dll). The installer then deploys the Rapuncel infostealer and the Alinubx.sys kernel driver, disguised as an NVIDIA component named nvfsflt64.sys and registered as the NvFsFilter service.
The driver acts as an EDR killer, containing a hardcoded list of 145 antivirus and EDR processes it attempts to terminate. LastPass explained the driver bypasses user-mode access checks by calling ObOpenObjectWithPointer in kernel mode, defeating Protected Process Light (PPL) protections that many security products rely on. The driver is currently not on Microsoft's vulnerable drivers blocklist and is signed through Microsoft's Windows Hardware Compatibility Publisher chain. The researchers noted Alinubx.sys also has capabilities for file and registry hiding, DLL injection, driver and process interception, traffic manipulation, and port redirection, though these were not activated in this campaign.
Oncetargeted for termination, the Rapuncel infostealer exfiltrates data, including credentials from 25 web browsers, data from 30 cryptocurrency wallets, Discord/Steam/Telegram session credentials, Windows Credential Manager contents, and documents with names containing keywords like 'password,' 'seed,' 'wallet,' or 'recovery.' It also captures screenshots from every connected monitor and detailed system information. It bypasses Google's app-bound encryption on Chrome and Edge by injecting a helper DLL and invoking its own Elevation Service. Stolen data is compressed and uploaded to an external endpoint at 2.26.126[.]50 over raw TCP. The malware persists across reboots via a Windows service, so any reactivated security tools are killed again.