SEO-optimized GitHub software-lure campaign pushing Rapuncel infostealer
Campaign
Summary
Hide ▲
Show ▼
An ongoing SEO-optimized GitHub lure campaign is impersonating software firms to push Rapuncel, expanding malware exposure across people searching for popular downloads. The operation uses fake repos that mimic LastPass and at least 39 other companies, turning routine software searches into a malware delivery path. Victims are redirected through download buttons and ZIP archives before the installer sideloads payloads and disables security tools. The chain matters because it combines brand impersonation, search manipulation, and an EDR-killing driver to improve successful infections and data theft.
Related Happenings
Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories
Malware Activity
H score26
First: 18.09.2026 18:19
Last: 18.09.2026 18:19
Sources 1
How related:
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
About this happening:
Rapuncel is being distributed through an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to lure people searching for well-known software, in...
Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories
Malware ActivityHow related: An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
About this happening: Rapuncel is being distributed through an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to lure people searching for well-known software, in...
MayaBot malware activity in BengalSEO
Malware Activity
H score10
First: 08.09.2026 11:43
Last: 08.09.2026 11:43
Sources 1
About this happening:
The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, incr...
MayaBot malware activity in BengalSEO
Malware ActivityAbout this happening: The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, incr...
Lurking Lizard trojanized 7-Zip installer campaign
Campaign
H score84
First: 09.07.2026 07:01
Last: 09.07.2026 07:01
Sources 1
About this happening:
A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
Lurking Lizard trojanized 7-Zip installer campaign
CampaignAbout this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret
Campaign
H score9
First: 23.06.2026 11:54
Last: 23.06.2026 11:54
Sources 1
About this happening:
A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...
PolinRider GitHub supply-chain campaign delivering BeaverTail and InvisibleFerret
CampaignAbout this happening: A North Korean supply-chain campaign dubbed PolinRider is injecting obfuscated JavaScript into compromised GitHub repositories, exposing developers to staged malware d...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityAbout this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Timeline
-
18.09.2026 18:19 2 articles · 1h ago
SEO-optimized GitHub repos impersonate software brands to push Rapuncel
Initial DisclosureLastPass and Delphos Labs identified an ongoing malware campaign that uses SEO-optimized GitHub repositories to impersonate LastPass and at least 39 other companies, steering people who search for LastPass Authenticator or other popular software into fake repos. The download flow redirects victims to payload-delivery servers that serve ZIP archives, a renamed copy of Microsoft Visual Studio CoreCLR Debugger, 'vsdbg.exe,' and a malicious DLL that sideloads Rapuncel and the Alinubx.sys kernel driver. The driver is disguised as an NVIDIA component named 'nvfsflt64.sys,' registers as the NvFsFilter service, and can terminate 145 antivirus and endpoint detection and response (EDR) products, while Rapuncel steals browser credentials, cryptocurrency wallet data, session credentials, Windows Credential Manager contents, matching documents, screenshots, and system information before exfiltrating the data to '2.26.126[.]50' and persisting via a Windows service.
Show sources
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer — www.bleepingcomputer.com — 18.09.2026 18:19
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer — www.bleepingcomputer.com — 18.09.2026 18:19