Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
BleepingComputer reports that fake LastPass Authenticator repositories hosted on GitHub are being used to push a new infostealer named Rapuncel. According to the report, the repositories impersonate the LastPass Authenticator, and the malware distributed through them is identified as Rapuncel. The source frames the activity as a malware distribution campaign operating through GitHub repositories rather than through the legitimate LastPass Authenticator. The available source text does not describe the number of repositories involved, how users were directed to them, what data Rapuncel collects, or which platforms or versions are targeted. It also does not state whether the repositories have been removed or whether LastPass or GitHub has responded. The only named elements are the impersonated product, LastPass Authenticator, the hosting platform, GitHub, and the infostealer, Rapuncel.
Developers who search GitHub for LastPass Authenticator tooling may encounter repositories that the source says distribute the Rapuncel infostealer instead.