← Back to Feed
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
September 18, 2026 · BleepingComputer · Severity: HIGH
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
Key Takeaways
- Fake LastPass Authenticator repositories on GitHub are pushing the Rapuncel information-stealing malware, tricking users who search for LastPass authentication tools into downloading malicious software.
- The fake repos mimic legitimate LastPass branding and documentation but deliver a trojan that steals browser credentials, session cookies, and cryptocurrency wallet data from unsuspecting victims.
- Users should verify the authenticity of GitHub repositories before downloading security tools, as threat actors increasingly impersonate well-known security brands to distribute information-stealing malware.