Plan
active
Fake LastPass GitHub repos distribute new Rapuncel infostealer
- Engineer — Plan: Add LastPass Authenticator and similar impersonation repos to your developer guidance; audit internal wikis and Slack channels for links to unofficial GitHub repos distributing security tools, and remind teams to verify publisher identity before cloning auth-related software.
- SOC/IR — Plan: Build or tune detections for Rapuncel infostealer behaviors once IOCs are published; in the meantime, hunt for developer endpoints that recently cloned security-tool repos from unverified GitHub accounts, as credential theft from dev machines is a high-value pivot.
- Leader — Learn: This campaign illustrates ongoing abuse of developer trust in open-source platforms; useful context for security awareness program updates and vendor-tool procurement policies, but no immediate leadership action required.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.