Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-19 · updated: 2026-09-19 · tags: [incident, government] · confidence: high · severity: low · affected_sectors: [government] · au_impact: false

An ongoing campaign uses SEO-optimised GitHub repositories impersonating well-known software vendors to push a previously undocumented infostealer called Rapuncel. LastPass and Delphos Labs, which uncovered it, say the repositories impersonate the password-manager brand and at least 40 other companies, and that victims arrive by searching for software such as LastPass Authenticator and following the fake repository links. Download buttons trigger a chain of redirects to payload servers that return ZIP archives inflated to as much as 148 MB to evade scan limits. The installer is a renamed copy of Microsoft's legitimate Visual Studio CoreCLR Debugger, vsdbg.exe, configured to sideload a malicious vsdbg.dll, which deploys Rapuncel alongside the kernel driver Alinubx.sys — disguised as an NVIDIA component, nvfsflt64.sys, registered as the NvFsFilter service. The driver carries a hardcoded list of 145 antivirus and EDR processes it terminates, and defeats Protected Process Light by opening processes in kernel mode.

Attribute Detail
Sector Government
Date 2026-09-19
Source BleepingComputer
Reliability Tier 2