:

FAKE LASTPASS REPOS DISTRIBUTE RAPUNCEL INFOSTEALER

DEV DESK1 MIN READ
FRI, SEP 18, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Attackers are running a malware campaign using fake GitHub repositories impersonating LastPass and other software vendors to distribute Rapuncel, a newly discovered information stealer.

The campaign leverages SEO optimization to make fraudulent repositories appear in search results, directing users to download malicious code instead of legitimate software. Rapuncel is a previously undocumented infostealer designed to harvest sensitive data from infected systems. The malware specifically targets credentials and personal information, posing a significant risk to users who download from the counterfeit repositories. Attackers have created multiple fake LastPass Authenticator repositories, capitalizing on the password manager's popularity to increase the likelihood of downloads. The SEO-optimized repositories rank prominently in search results, making them difficult to distinguish from legitimate sources. Security researchers recommend verifying GitHub repository authenticity by checking official organization badges, repository URLs, and author accounts. Users should download software exclusively from official sources or verified vendor repositories. The discovery highlights ongoing risks associated with supply chain attacks and the importance of code repository vigilance.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

An 18-year-old Swedish teenager known as Chai has been sentenced to over 10 years in prison for attempted murder, rape, and aggravated assault committed online against victims in Germany and Australia.

JUST NOWAI Desk

Image-sharing platform Gyazo confirmed a data breach after attackers exploited a server vulnerability to steal 23.6 million user records. The company has launched an investigation into the incident.

JUST NOWSecurity Desk

A liquefied natural gas tanker transporting US fuel to Europe experienced a systems failure that crew members suspect was a cyberattack. The incident marks a significant security concern for critical energy infrastructure.

2H AGOSecurity Desk

A developer has published criticism of passkeys, the passwordless authentication method gaining industry backing. The post has sparked substantial discussion in tech communities.

2H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.