Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
BLUF
Threat actors are distributing the undocumented Rapuncel infostealer via SEO-optimized GitHub repos impersonating LastPass Authenticator.
NEWS
A new malware campaign utilizes SEO-optimized GitHub repositories to impersonate trusted software firms and deliver the previously undocumented Rapuncel information stealer. This technique specifically targets users searching for LastPass Authenticator tools, bypassing traditional security warnings through platform trust. Security researchers have flagged this as an evolving tactic leveraging developer ecosystems for malware distribution.
Why I Care
Organizations and individuals relying on GitHub for software downloads face increased risk of credential theft and data exfiltration. The campaign exploits user trust in open-source platforms, potentially compromising sensitive authentication data across affected sectors. This trend signals a shift toward abusing legitimate development tools for malicious distribution.
Next Steps
Developers and users must verify repository ownership against official vendor sources before installing any authenticator tools. Security operations teams should update endpoint detection rules to identify Rapuncel indicators of compromise immediately. IT administrators should audit GitHub access logs for suspicious repository cloning activity within the next 48 hours.
Source: BleepingComputer ·