Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

Refract AI Intelligence Digest

BLUF

Threat actors are distributing the undocumented Rapuncel infostealer via SEO-optimized GitHub repos impersonating LastPass Authenticator.

NEWS

A new malware campaign utilizes SEO-optimized GitHub repositories to impersonate trusted software firms and deliver the previously undocumented Rapuncel information stealer. This technique specifically targets users searching for LastPass Authenticator tools, bypassing traditional security warnings through platform trust. Security researchers have flagged this as an evolving tactic leveraging developer ecosystems for malware distribution.

Why I Care

Organizations and individuals relying on GitHub for software downloads face increased risk of credential theft and data exfiltration. The campaign exploits user trust in open-source platforms, potentially compromising sensitive authentication data across affected sectors. This trend signals a shift toward abusing legitimate development tools for malicious distribution.

Next Steps

Developers and users must verify repository ownership against official vendor sources before installing any authenticator tools. Security operations teams should update endpoint detection rules to identify Rapuncel indicators of compromise immediately. IT administrators should audit GitHub access logs for suspicious repository cloning activity within the next 48 hours.

An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.