Executive Summary

In September 2026, cybercriminals launched a sophisticated malware campaign using SEO-optimized fake GitHub repositories impersonating LastPass and 39 other legitimate software companies. The attack delivers the previously undocumented Rapuncel infostealer along with a Microsoft-signed kernel driver capable of disabling 145 antivirus and EDR products. Victims searching for popular software like LastPass Authenticator are redirected through malicious GitHub repos to download ZIP archives containing the malware, which steals credentials from 25 browsers, 30 cryptocurrency wallets, and sensitive documents while maintaining persistence across system reboots.

This incident highlights the growing sophistication of supply chain attacks targeting trusted development platforms like GitHub, demonstrating how threat actors exploit SEO manipulation and legitimate code-signing certificates to bypass security controls and establish persistent access to victim systems.

Why This Matters Now

This campaign represents a dangerous evolution in software supply chain attacks, exploiting trusted platforms like GitHub and legitimate Microsoft-signed drivers to bypass modern security defenses, making traditional detection methods ineffective against these sophisticated multi-stage attacks.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Rapuncel uses a Microsoft-signed kernel driver that operates at kernel level to terminate 145 different antivirus and EDR products by bypassing Protected Process Light (PPL) protections.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely limit the attacker's ability to establish external communication channels and reduce lateral movement scope across cloud workloads. The segmented architecture could constrain the malware's reach to distributed infrastructure and cryptocurrency wallet access points.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The malware's ability to establish initial foothold in cloud workloads would likely be constrained through workload isolation and controlled access paths to reduce blast radius.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The kernel driver's ability to access distributed cloud resources and services would likely be limited through identity-aware segmentation that restricts privilege scope across workloads.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The malware's ability to move laterally between cloud workloads and services would likely be constrained through east-west traffic enforcement that limits inter-workload communication paths.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The malware's command and control communications would likely be constrained through visibility controls that limit unauthorized external connections and reduce communication channels to attacker infrastructure.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The malware's data exfiltration capabilities would likely be limited through controlled egress policies that constrain outbound data flows and reduce unauthorized external data transfers.

Impact (Mitigations)

The malware's persistent access to distributed cryptocurrency wallets and credential stores would likely be constrained to isolated workload segments, reducing the scope of ongoing compromise.

Impact at a Glance

Affected Business Functions

  • Identity and Access Management
  • Password Management Systems
  • Cryptocurrency Asset Management
  • Secure Communications
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Comprehensive credential theft including passwords from 25 web browsers, cryptocurrency wallet data from 30 wallet applications, session tokens for Discord, Steam, and Telegram, Windows Credential Manager contents, sensitive documents containing passwords and recovery phrases, and screenshots from all connected monitors. The malware specifically targets high-value authentication and financial data.

Recommended Actions

  • Implement Egress Security & Policy Enforcement to block unauthorized outbound connections to malicious C2 infrastructure like 2.26.126[.]50
  • Deploy Cloud Firewall (ACF) with URL filtering to prevent access to fake GitHub repositories and malicious download sites
  • Enable Threat Detection & Anomaly Response capabilities to identify kernel driver deployment and EDR termination activities
  • Establish Zero Trust Segmentation with least privilege access to limit the impact of compromised endpoints
  • Implement Encrypted Traffic (HPE) controls to secure data in transit and prevent credential exfiltration over unencrypted channels

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image