← Back to Tech & Science

Fake LastPass Installers on GitHub Deploy Kernel-Level Malware to Bypass Security

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

SAN FRANCISCO — Unknown attackers have distributed fraudulent LastPass installers through the code repository platform GitHub, deploying a sophisticated kernel-level driver designed to disable security software and steal sensitive user data. The campaign, detected on Sept. 21, 2026, marks a significant escalation in brand-spoofing tactics targeting password managers.

The malicious files, disguised as legitimate updates for the LastPass browser extension, were hosted on GitHub repositories that appeared credible to users seeking the latest software versions. Once executed, the installers dropped a custom kernel-mode driver onto victim systems. This driver operates at the deepest level of the operating system, granting it the authority to terminate active security processes, including antivirus scanners and endpoint detection tools, before they can intervene.

Following the neutralization of defensive measures, the malware deploys a payload identified as 'Rapuncel.' This information-stealing module is engineered to harvest credentials, financial data, and session tokens stored within the compromised password vaults. The attackers leveraged Cloudflare servers to host the malicious binaries, utilizing the content delivery network's infrastructure to mask the origin of the traffic and evade standard IP-based blocking mechanisms.

The operation appears driven by opportunistic motives, exploiting the global trust placed in LastPass as a leading security provider. By impersonating a well-known brand, the attackers increased the likelihood of successful downloads among users who may have bypassed cautionary checks due to the perceived legitimacy of the source. The use of GitHub, a platform widely used by developers for open-source collaboration, further complicated detection, as the repository hosting the files mimicked standard project structures.

Security researchers noted that the kernel-level nature of the driver makes traditional signature-based detection ineffective, requiring behavioral analysis and memory scanning to identify the intrusion. The malware's ability to disable security tools before executing its payload creates a window of vulnerability where data exfiltration can occur undetected for extended periods.

LastPass has not yet issued a public statement regarding the specific campaign or confirmed whether any user accounts were directly compromised by the fake installers. The company previously warned users against downloading software from unofficial sources, but the sophistication of this spoofing effort suggests that even vigilant users may struggle to distinguish the malicious files from genuine updates.

The full scope of the attack remains unclear as investigators work to identify the number of affected systems globally. Questions persist regarding whether the attackers have established a command-and-control infrastructure capable of long-term persistence or if the campaign was a one-time distribution event. Additionally, it is unknown if the 'Rapuncel' malware has been linked to previous cybercrime operations or represents a new threat actor entering the landscape.

Discussion

0 / 2000