Fake LastPass downloads spread stealer that kills 145 security tools
A kit impersonating 40+ brands on GitHub used a Microsoft-signed driver to disable security software before installing the Rapuncel infostealer.
By Dev Okafor · Published · Updated · 4 min read

A fake LastPass Authenticator on GitHub led researchers to a campaign impersonating at least 40 companies, SecurityWeek reports.
How it worked
- LastPass spotted the fake GitHub page on August 13, 2026. It ranked highly in searches for "LastPass Authenticator download" and showed fake "VirusTotal Approved" badges.
- Victims downloaded an archive containing a renamed Microsoft debugging tool that loaded the attacker's code.
- The malware installed a kernel driver, disguised as an NVIDIA component and signed through Microsoft's hardware program, that could shut down 145 antivirus and security products.
- With defences disabled, it deployed an infostealer LastPass calls Rapuncel.
LastPass stresses that none of its own systems were compromised, Security Affairs notes.
Why it matters
Signed drivers are trusted by Windows, so this technique — known as "bring your own vulnerable driver" — lets malware disable protection quietly. Search engine poisoning means even careful users can land on fake download pages.
How to stay safe
- Download software only from the vendor's official site or app store, not from search results or GitHub mirrors.
- Be wary of "trust badges" on download pages — they are easy to fake.
- Businesses should block known vulnerable drivers using Microsoft's driver blocklist.



