Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
Executive Summary
A malware campaign leverages SEO‑optimized GitHub repositories that masquerade as legitimate software vendors, including a fake LastPass Authenticator, to distribute a previously undocumented information stealer named Rapuncel. The attackers use these repos to lure users into downloading the malicious package, which harvests credentials and other sensitive data. The operation demonstrates how open‑source platforms can be weaponized for credential theft.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-18T15:19:06+00:00 - Category: threat-intel
Original Description: An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]
"If we learn to open our hearts, anyone, including the people who drive us crazy, can be our teacher."
— Pema Chodron