Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
Fake LastPass Authenticator GitHub repos spread new Rapuncel infostealer alongside a Microsoft-signed kernel driver that kills 145 antivirus and EDR products.
LastPass and Delphos Labs uncovered an ongoing campaign using SEO-optimized GitHub repositories impersonating LastPass and at least 39 other companies to deliver the previously undocumented Rapuncel infostealer. Oversized ZIPs up to 148MB carry vsdbg.exe sideloading a malicious vsdbg.dll, which deploys Rapuncel and the Alinubx.sys kernel driver (signed via Microsoft's Windows Hardware Compatibility Publisher chain) that terminates 145 AV/EDR processes and bypasses Protected Process Light via kernel-mode handle opens. Rapuncel steals credentials from 25 browsers, 30 cryptocurrency wallets, Discord, Steam, and Telegram sessions, bypasses Chrome's app-bound encryption via DLL injection, and exfiltrates data to 2.26.126[.]50 over raw TCP; researchers assess with moderate confidence it is a BoryptGrab variant.