ATTACKERS used a fake GitHub organisation impersonating LastPass to distribute a counterfeit LastPass Authenticator. Identified by LastPass’s Threat Intelligence, Mitigation, and Escalation team on 13 August 2026, the operation appeared in searches for “LastPass Authenticator download” and used genuine branding and bogus trust badges, including “VirusTotal Approved”. LastPass said no company systems, services or customer vaults were compromised; the lure was distributed outside its channels.
Delphos Labs’ analysis found the same infrastructure impersonating at least 40 companies, indicating a malware-as-a-service operation. Redirects through apparently broken GitHub Pages led victims to changing download servers, while oversized ZIP archives used junk DLLs to evade automated scanning.
The delivered malware, tracked by LastPass as Rapuncel, abused a renamed Microsoft debugging tool to load a malicious DLL, gain SYSTEM privileges and install a kernel driver disguised as an NVIDIA component. Although the driver had a valid Microsoft Windows Hardware Compatibility Publisher signature and a clean VirusTotal result, Delphos traced it to the known CcProtect.sys driver, renamed Alinubx.sys. Its functionality allowed the malware to disable 145 antivirus and endpoint-detection products.
The infostealer could then collect passwords from more than 25 browsers, cryptocurrency-wallet files from over 30 applications, Discord tokens, Steam sessions, Telegram data, Windows Credential Manager contents and screenshots. Delphos reported the sample to Microsoft on 19 August; Microsoft referred it to its driver-blocklist process, and the article said Alinubx.sys was not yet listed.
Users should obtain LastPass Authenticator only from lastpass.com or official app stores and investigate systems where software was downloaded from the fake GitHub pages.