Find notable cyber news and cases, enriched with sources, timelines, and signals.

Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories

Malware Activity
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

Rapuncel is being distributed through an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to lure people searching for well-known software, increasing the risk of credential theft and wallet theft on infected Windows devices. The payload chain combines a sideloading installer, a Microsoft-signed kernel driver, and a persistence mechanism that helps the malware keep running after reboots. Once security tools are disabled, the infostealer can collect browser credentials, session tokens, screenshots, and system information before exfiltrating the data.

Related Happenings

SEO-optimized GitHub software-lure campaign pushing Rapuncel infostealer

Campaign
H score34 First: 18.09.2026 18:19 Last: 18.09.2026 18:19 Sources 1

How related: An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.

About this happening: An ongoing SEO-optimized GitHub lure campaign is impersonating software firms to push Rapuncel, expanding malware exposure across people searching for popular download...

MayaBot malware activity in BengalSEO

Malware Activity
H score10 First: 08.09.2026 11:43 Last: 08.09.2026 11:43 Sources 1

About this happening: The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, incr...

SynkLoader Microsoft Teams help-desk phishing campaign

Campaign
H score35 First: 21.08.2026 21:01 Last: 21.08.2026 21:01 Sources 1

About this happening: The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open...

BoryptGrab infostealer variant delivered via fake GitHub repositories

Malware Activity
H score30 First: 14.07.2026 22:15 Last: 14.07.2026 22:15 Sources 1

About this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...

Rollup polyfill npm package malware activity for remote access and data theft

Malware Activity
H score16 First: 03.07.2026 19:07 Last: 03.07.2026 19:07 Sources 1

About this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...

Timeline

  1. 18.09.2026 18:19 2 articles · 1h ago

    LastPass and Delphos Labs uncover Rapuncel campaign on fake GitHub repositories

    Initial Disclosure

    LastPass and Delphos Labs uncovered an ongoing malware campaign that uses SEO-optimized GitHub repositories to impersonate software brands, including LastPass, and lure people searching for LastPass Authenticator or other popular software into fake repos that distribute Rapuncel, a previously undocumented infostealer, together with a Microsoft-signed kernel driver that can terminate 145 antivirus and EDR products.

    Show sources