An ongoing campaign uses SEO-optimised GitHub repositories impersonating well-known software vendors to push a previously undocumented infostealer called Rapuncel. LastPass and Delphos Labs, which uncovered it, say the repositories impersonate the password-manager brand and at least 40 other companies, and that victims arrive by searching for software such as LastPass Authenticator and following the fake repository links. Download buttons trigger a chain of redirects to payload servers that return ZIP archives inflated to as much as 148 MB to evade scan limits. The installer is a renamed copy of Microsoft's legitimate Visual Studio CoreCLR Debugger, vsdbg.exe, configured to sideload a malicious vsdbg.dll, which deploys Rapuncel alongside the kernel driver Alinubx.sys — disguised as an NVIDIA component, nvfsflt64.sys, registered as the NvFsFilter service. The driver carries a hardcoded list of 145 antivirus and EDR processes it terminates, and defeats Protected Process Light by opening processes in kernel mode.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-19 |
| Source | BleepingComputer |
| Reliability | Tier 2 |