← Back to Feed

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

September 18, 2026 · BleepingComputer · Severity: HIGH

An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.

Key Takeaways

  • Fake LastPass Authenticator repositories on GitHub are pushing the Rapuncel information-stealing malware, tricking users who search for LastPass authentication tools into downloading malicious software.
  • The fake repos mimic legitimate LastPass branding and documentation but deliver a trojan that steals browser credentials, session cookies, and cryptocurrency wallet data from unsuspecting victims.
  • Users should verify the authenticity of GitHub repositories before downloading security tools, as threat actors increasingly impersonate well-known security brands to distribute information-stealing malware.
☕ Buy a Coffee