Find notable cyber news and cases, enriched with sources, timelines, and signals.

SEO-optimized GitHub software-lure campaign pushing Rapuncel infostealer

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

An ongoing SEO-optimized GitHub lure campaign is impersonating software firms to push Rapuncel, expanding malware exposure across people searching for popular downloads. The operation uses fake repos that mimic LastPass and at least 39 other companies, turning routine software searches into a malware delivery path. Victims are redirected through download buttons and ZIP archives before the installer sideloads payloads and disables security tools. The chain matters because it combines brand impersonation, search manipulation, and an EDR-killing driver to improve successful infections and data theft.

Related Happenings

Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories

Malware Activity
H score26 First: 18.09.2026 18:19 Last: 18.09.2026 18:19 Sources 1

How related: An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.

About this happening: Rapuncel is being distributed through an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to lure people searching for well-known software, in...

MayaBot malware activity in BengalSEO

Malware Activity
H score10 First: 08.09.2026 11:43 Last: 08.09.2026 11:43 Sources 1

About this happening: The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, incr...

Lurking Lizard trojanized 7-Zip installer campaign

Campaign
H score84 First: 09.07.2026 07:01 Last: 09.07.2026 07:01 Sources 1

About this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...

PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret

Campaign
H score9 First: 23.06.2026 11:54 Last: 23.06.2026 11:54 Sources 1

About this happening: A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...

Rust-based clipboard hijacker spreading via fake crypto tools

Malware Activity
H score13 First: 18.06.2026 18:00 Last: 18.06.2026 18:00 Sources 1

About this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...

Timeline

  1. 18.09.2026 18:19 2 articles · 1h ago

    SEO-optimized GitHub repos impersonate software brands to push Rapuncel

    Initial Disclosure

    LastPass and Delphos Labs identified an ongoing malware campaign that uses SEO-optimized GitHub repositories to impersonate LastPass and at least 39 other companies, steering people who search for LastPass Authenticator or other popular software into fake repos. The download flow redirects victims to payload-delivery servers that serve ZIP archives, a renamed copy of Microsoft Visual Studio CoreCLR Debugger, 'vsdbg.exe,' and a malicious DLL that sideloads Rapuncel and the Alinubx.sys kernel driver. The driver is disguised as an NVIDIA component named 'nvfsflt64.sys,' registers as the NvFsFilter service, and can terminate 145 antivirus and endpoint detection and response (EDR) products, while Rapuncel steals browser credentials, cryptocurrency wallet data, session credentials, Windows Credential Manager contents, matching documents, screenshots, and system information before exfiltrating the data to '2.26.126[.]50' and persisting via a Windows service.

    Show sources