CuraSec

Plan active

Fake LastPass GitHub repos distribute new Rapuncel infostealer

2026-09-19 14:22 UTC · BleepingComputer · read the source ↗ #infostealer#supply-chain#social-engineering
  • Engineer — Plan: Add LastPass Authenticator and similar impersonation repos to your developer guidance; audit internal wikis and Slack channels for links to unofficial GitHub repos distributing security tools, and remind teams to verify publisher identity before cloning auth-related software.
  • SOC/IR — Plan: Build or tune detections for Rapuncel infostealer behaviors once IOCs are published; in the meantime, hunt for developer endpoints that recently cloned security-tool repos from unverified GitHub accounts, as credential theft from dev machines is a high-value pivot.
  • Leader — Learn: This campaign illustrates ongoing abuse of developer trust in open-source platforms; useful context for security awareness program updates and vendor-tool procurement policies, but no immediate leadership action required.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.