Malicious LastPass Authenticator Repos On GitHub Spread New Rapuncel Infostealer
By 813 Staff
Tech industry sources confirm Malicious LastPass Authenticator Repos On GitHub Spread New Rapuncel Infostealer, according to BleepingComputer (@BleepinComputer) (in the last 24 hours).
Source: https://x.com/BleepinComputer/status/2100967934839415274
Unlike the crude typosquatting campaigns that have long littered GitHub with fake credential-stealing tools, this week's operation arrives with a polish that has unnerved even seasoned threat researchers. According to BleepingComputer (@BleepinComputer), attackers are now publishing counterfeit LastPass Authenticator repositories that deliver a previously undocumented infostealer dubbed Rapuncel, and the rollout has been anything but smooth for defenders trying to stamp it out quickly.
The campaign, flagged on September 18, marks a shift in how the malware is distributed. Rather than relying on phishing emails or compromised websites, the operators are embedding themselves in developer infrastructure, dressing up malicious code as an authenticator tool for the password manager LastPass. Internal documents reviewed by researchers close to the investigation indicate the repositories were crafted to survive casual inspection, with commit histories and README files designed to mimic legitimate open-source projects. Engineers close to the project say the repos targeted developers searching for multi-factor authentication utilities, a demographic that tends to hold privileged access at their employers.
Rapuncel itself is the more significant concern. Unlike commodity stealers that grab browser credentials and move on, samples analyzed so far appear capable of harvesting session tokens, cryptocurrency wallet data, and stored authentication secrets. That combination suggests the operators are positioning for account takeover at scale, not opportunistic smash-and-grab theft. It remains unconfirmed whether the malware includes any persistence mechanism or command-and-control fallback, and researchers have not publicly attributed the campaign to a known group.
Why it matters is straightforward. Software supply chain attacks routed through code-hosting platforms are difficult to police because trust is baked into the developer workflow. A fake repository that looks functional can sit online for days before takedown, and every clone or fork extends its reach. For security teams, the incident reinforces that vetting dependencies and repositories is now as important as endpoint protection.
What happens next remains fluid. GitHub has removed at least a portion of the identified repositories, though it is unclear how many were taken down versus still live at the time of reporting. LastPass has not issued a public statement. Analysts expect copycat campaigns to follow within weeks, and the appearance of Rapuncel suggests its operators are still refining the tool. Until attribution or a full technical write-up emerges, treat any third-party authenticator repo as unverified.
Source: https://x.com/BleepinComputer/status/2100967934839415274
