Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

Fake LastPass GitHub App Delivered Malware That Killed 145 Tools

Published 23 September 2026

A fake LastPass Authenticator page on GitHub delivered malware that installed a Microsoft-signed Windows driver capable of terminating 145 antivirus and endpoint security products, according to LastPass and Delphos Labs. The campaign also used the malware, which LastPass tracks as Rapuncel, to steal credentials and other data from infected computers. LastPass said its threat intelligence team discovered the fake page on August 13, 2026. It appeared in search results for the authenticator and used LastPass branding to look legitimate. Researchers said the page was part of a broader operation impersonating at least 40 companies. The number of people who downloaded the malware or were infected has not been reported. The fake download led through a series of GitHub pages to an attacker-controlled server, which supplied a large archive. Inside, a renamed Microsoft debugging tool loaded a malicious file in the same folder, a technique known as DLL sideloading. The malware then installed a kernel driver named Alinubx.sys, disguised as an NVIDIA component. Its hardcoded list included 145 security products, which the driver could terminate from the Windows kernel.

0:00 / 0:00