Executive Summary
In September 2026, cybercriminals launched a sophisticated malware campaign using SEO-optimized fake GitHub repositories impersonating LastPass and 39 other legitimate software companies. The attack delivers the previously undocumented Rapuncel infostealer along with a Microsoft-signed kernel driver capable of disabling 145 antivirus and EDR products. Victims searching for popular software like LastPass Authenticator are redirected through malicious GitHub repos to download ZIP archives containing the malware, which steals credentials from 25 browsers, 30 cryptocurrency wallets, and sensitive documents while maintaining persistence across system reboots.
This incident highlights the growing sophistication of supply chain attacks targeting trusted development platforms like GitHub, demonstrating how threat actors exploit SEO manipulation and legitimate code-signing certificates to bypass security controls and establish persistent access to victim systems.
Why This Matters Now
This campaign represents a dangerous evolution in software supply chain attacks, exploiting trusted platforms like GitHub and legitimate Microsoft-signed drivers to bypass modern security defenses, making traditional detection methods ineffective against these sophisticated multi-stage attacks.
Attack Path Analysis
Attackers leveraged SEO-optimized fake GitHub repositories to distribute Rapuncel infostealer disguised as legitimate LastPass Authenticator software. The malware deployed a Microsoft-signed kernel driver to disable 145 antivirus/EDR products, then exfiltrated credentials from browsers, cryptocurrency wallets, and sensitive documents via HTTP over raw TCP to external infrastructure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Victims searched for LastPass Authenticator software and accessed SEO-optimized fake GitHub repositories impersonating legitimate software vendors, downloading ZIP archives containing DLL sideloading malware
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Hijack Execution Flow: DLL Side-Loading
Impair Defenses: Disable or Modify Tools
Credentials from Password Stores: Credentials from Web Browsers
Screen Capture
Create or Modify System Process: Windows Service
Exfiltration Over C2 Channel
Masquerading: Match Legitimate Name or Location
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Development Security
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
CISA ZTMM 2.0 – Data Categorization and Sensitivity Labeling
Control ID: DA.L1-02
DORA – ICT Third-Party Risk Management
Control ID: Article 11
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
High risk from GitHub-hosted Rapuncel infostealer targeting software downloads, bypassing EDR protection, stealing credentials from development environments and repositories.
Financial Services
Critical exposure as Rapuncel targets 30 cryptocurrency wallets and banking credentials, with kernel driver disabling security controls protecting financial data.
Information Technology/IT
Severe impact from EDR-killing capabilities targeting 145 security products, credential theft from system administrators, and persistence across IT infrastructure reboots.
Computer/Network Security
Direct threat to security operations as malware specifically defeats Protected Process Light defenses and terminates antivirus/EDR solutions through kernel-level access.
Sources
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealerhttps://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/Verified
- LastPass and Delphos Labs Joint Report on Rapuncel Infostealerhttps://blog.lastpass.com/posts/lastpass-delphos-report-rapuncel-infostealerVerified
- Microsoft Security Intelligence on GitHub Repository Abusehttps://www.microsoft.com/en-us/security/blog/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely limit the attacker's ability to establish external communication channels and reduce lateral movement scope across cloud workloads. The segmented architecture could constrain the malware's reach to distributed infrastructure and cryptocurrency wallet access points.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The malware's ability to establish initial foothold in cloud workloads would likely be constrained through workload isolation and controlled access paths to reduce blast radius.
Control: Zero Trust Segmentation
Mitigation: The kernel driver's ability to access distributed cloud resources and services would likely be limited through identity-aware segmentation that restricts privilege scope across workloads.
Control: East-West Traffic Security
Mitigation: The malware's ability to move laterally between cloud workloads and services would likely be constrained through east-west traffic enforcement that limits inter-workload communication paths.
Control: Multicloud Visibility & Control
Mitigation: The malware's command and control communications would likely be constrained through visibility controls that limit unauthorized external connections and reduce communication channels to attacker infrastructure.
Control: Egress Security & Policy Enforcement
Mitigation: The malware's data exfiltration capabilities would likely be limited through controlled egress policies that constrain outbound data flows and reduce unauthorized external data transfers.
The malware's persistent access to distributed cryptocurrency wallets and credential stores would likely be constrained to isolated workload segments, reducing the scope of ongoing compromise.
Impact at a Glance
Affected Business Functions
- Identity and Access Management
- Password Management Systems
- Cryptocurrency Asset Management
- Secure Communications
Estimated downtime: 3 days
Estimated loss: $50,000
Comprehensive credential theft including passwords from 25 web browsers, cryptocurrency wallet data from 30 wallet applications, session tokens for Discord, Steam, and Telegram, Windows Credential Manager contents, sensitive documents containing passwords and recovery phrases, and screenshots from all connected monitors. The malware specifically targets high-value authentication and financial data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to block unauthorized outbound connections to malicious C2 infrastructure like 2.26.126[.]50
- • Deploy Cloud Firewall (ACF) with URL filtering to prevent access to fake GitHub repositories and malicious download sites
- • Enable Threat Detection & Anomaly Response capabilities to identify kernel driver deployment and EDR termination activities
- • Establish Zero Trust Segmentation with least privilege access to limit the impact of compromised endpoints
- • Implement Encrypted Traffic (HPE) controls to secure data in transit and prevent credential exfiltration over unencrypted channels



