Fake LastPass GitHub App Delivered Malware That Killed 145 Tools
A fake LastPass Authenticator page on GitHub delivered malware that installed a Microsoft-signed Windows driver capable of terminating 145 antivirus and endpoint security products, according to LastPass and Delphos Labs. The campaign also used the malware, which LastPass tracks as Rapuncel, to steal credentials and other data from infected computers. LastPass said its threat intelligence team discovered the fake page on August 13, 2026. It appeared in search results for the authenticator and used LastPass branding to look legitimate. Researchers said the page was part of a broader operation impersonating at least 40 companies. The number of people who downloaded the malware or were infected has not been reported. The fake download led through a series of GitHub pages to an attacker-controlled server, which supplied a large archive. Inside, a renamed Microsoft debugging tool loaded a malicious file in the same folder, a technique known as DLL sideloading. The malware then installed a kernel driver named Alinubx.sys, disguised as an NVIDIA component. Its hardcoded list included 145 security products, which the driver could terminate from the Windows kernel.