Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories
Malware Activity
Summary
Hide ▲
Show ▼
Rapuncel is being distributed through an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to lure people searching for well-known software, increasing the risk of credential theft and wallet theft on infected Windows devices. The payload chain combines a sideloading installer, a Microsoft-signed kernel driver, and a persistence mechanism that helps the malware keep running after reboots. Once security tools are disabled, the infostealer can collect browser credentials, session tokens, screenshots, and system information before exfiltrating the data.
Related Happenings
SEO-optimized GitHub software-lure campaign pushing Rapuncel infostealer
Campaign
H score34
First: 18.09.2026 18:19
Last: 18.09.2026 18:19
Sources 1
How related:
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
About this happening:
An ongoing SEO-optimized GitHub lure campaign is impersonating software firms to push Rapuncel, expanding malware exposure across people searching for popular download...
SEO-optimized GitHub software-lure campaign pushing Rapuncel infostealer
CampaignHow related: An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
About this happening: An ongoing SEO-optimized GitHub lure campaign is impersonating software firms to push Rapuncel, expanding malware exposure across people searching for popular download...
MayaBot malware activity in BengalSEO
Malware Activity
H score10
First: 08.09.2026 11:43
Last: 08.09.2026 11:43
Sources 1
About this happening:
The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, incr...
MayaBot malware activity in BengalSEO
Malware ActivityAbout this happening: The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, incr...
SynkLoader Microsoft Teams help-desk phishing campaign
Campaign
H score35
First: 21.08.2026 21:01
Last: 21.08.2026 21:01
Sources 1
About this happening:
The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open...
SynkLoader Microsoft Teams help-desk phishing campaign
CampaignAbout this happening: The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open...
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware Activity
H score30
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
BoryptGrab infostealer variant delivered via fake GitHub repositories
Malware ActivityAbout this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...
Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
H score16
First: 03.07.2026 19:07
Last: 03.07.2026 19:07
Sources 1
About this happening:
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Rollup polyfill npm package malware activity for remote access and data theft
Malware ActivityAbout this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Timeline
-
18.09.2026 18:19 2 articles · 1h ago
LastPass and Delphos Labs uncover Rapuncel campaign on fake GitHub repositories
Initial DisclosureLastPass and Delphos Labs uncovered an ongoing malware campaign that uses SEO-optimized GitHub repositories to impersonate software brands, including LastPass, and lure people searching for LastPass Authenticator or other popular software into fake repos that distribute Rapuncel, a previously undocumented infostealer, together with a Microsoft-signed kernel driver that can terminate 145 antivirus and EDR products.
Show sources
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer — www.bleepingcomputer.com — 18.09.2026 18:19
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer — www.bleepingcomputer.com — 18.09.2026 18:19