Fake GitHub Repos Spread New Infostealer to Bypass Security Tools

A new malware campaign uses fake software repositories to disable antivirus programs and steal sensitive user data.
Cybercriminals are leveraging fake GitHub repositories to distribute a previously undocumented information stealer known as Rapuncel. The campaign impersonates popular software brands, including LastPass, to trick users into downloading malicious files that disable security protections before stealing sensitive data.
Researchers from LastPass and Delphos Labs identified the operation, which targets at least 39 different companies. The attack chain begins with search engine optimization tricks that make fake repositories appear as top results, leading victims to download what they believe are legitimate applications.
Disabling security software with signed drivers
The malicious payload includes a kernel driver disguised as an NVIDIA component. This driver is signed by Microsoft’s Hardware Compatibility Publisher, allowing it to bypass standard security checks. It contains a hardcoded list of 145 antivirus and endpoint detection products that it systematically terminates.
By operating in kernel mode, the driver bypasses user-mode protections that most security software relies on. This allows the malware to kill protected processes and prevent security tools from reacting or reinstating themselves after a reboot.
Stealing credentials from browsers and wallets
Once security software is disabled, the Rapuncel infostealer collects a wide range of sensitive information. This includes credentials from 25 web browsers, data from 30 cryptocurrency wallets, and session tokens for platforms like Discord, Steam, and Telegram.
The malware also targets files with names containing keywords like password or recovery, and captures screenshots from all connected monitors. To bypass modern browser encryption, it injects code directly into the browser applications to access stored credentials.
Avoiding fake repositories and promoted links
BleepingComputer reported that the stolen data is compressed and sent to external servers over raw TCP connections. The malware persists across reboots by installing itself as a Windows service, ensuring it remains active even if a user attempts to restart the computer.
Experts recommend that users only download software from official vendor websites. Avoiding dubious GitHub repositories and being cautious of promoted search results can significantly reduce the risk of falling victim to this deceptive campaign.






