Ethical Hacking News
A fake LastPass impersonation on GitHub has led to the disruption of 145 security tools, highlighting the growing threat of brand impersonation attacks. The attack, which involved a malicious infostealer, compromised the credentials of over 100,000 websites and demonstrated the need for users to be vigilant when downloading software or authenticators from the internet.
145 security tools were disrupted due to a fake LastPass impersonation attack on GitHub. A malicious infostealer, Rapuncel, was used to steal sensitive information from computers that downloaded the fake authenticator. The attack relied on tactics such as padding and a valid Microsoft Windows Hardware Compatibility Publisher signature to evade security checks. The attack highlights the growing threat of brand impersonation attacks and the need for users to be vigilant when downloading software or authenticators from the internet.
In a shocking incident that highlights the growing threat of brand impersonation attacks, a fake LastPass impersonation on GitHub has led to the disruption of 145 security tools. The attack, which was discovered by LastPass's Threat Intelligence, Mitigation, and Escalation team in partnership with Delphos Labs, involved a malicious infostealer that compromised the credentials of over 100,000 websites.
The attack began when an attacker spoofed LastPass on GitHub, creating a fake authenticator that looked and felt like the real thing. The fake authenticator was distributed through a series of GitHub Pages accounts that were designed to mimic the appearance of legitimate LastPass pages. However, upon closer inspection, the fake authenticator was revealed to contain malicious code that would compromise the security tools of those who downloaded it.
The malicious infostealer, which was later identified as Rapuncel, was designed to steal sensitive information from the computers of those who downloaded the fake authenticator. The infostealer was able to bypass security checks and disable 145 security products, including antivirus and EDR software, before stealing sensitive information such as passwords, wallet files, and Discord tokens.
The attack was particularly effective because it relied on a combination of tactics, including padding, which was used to evade automated scanners, and a valid Microsoft Windows Hardware Compatibility Publisher signature, which was used to bypass security checks. The attackers also used a toolkit that targeted around 40 other companies, making it a sophisticated and far-reaching attack.
In response to the attack, LastPass's Threat Intelligence, Mitigation, and Escalation team worked with Delphos Labs to identify and disrupt the malicious campaign. The team was able to flag the malicious code to Microsoft, which responded by redirecting the report to a separate blocklist submission channel.
However, despite the efforts of the LastPass team and Microsoft, the attack was able to evade detection for several weeks. The bigger lesson from this attack is that no brand or logo is safe from impersonation, and that a Microsoft signature does not automatically mean a driver is safe.
The attack highlights the growing threat of brand impersonation attacks and the need for users to be vigilant when downloading software or authenticators from the internet. It also highlights the importance of relying on multiple security checks and the need for organizations to stay up-to-date with the latest security patches and updates.
In conclusion, the fake LastPass impersonation on GitHub that led to the disruption of 145 security tools is a stark reminder of the dangers of brand impersonation attacks and the need for users to be vigilant when downloading software or authenticators from the internet. As the threat landscape continues to evolve, it is essential that users and organizations take steps to protect themselves from such attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/Infostealer-Campaign-How-a-Fake-LastPass-Impersonation-on-GitHub-Led-to-the-Disruption-of-145-Security-Tools-ehn.shtml
https://securityaffairs.com/199577/malware/fake-lastpass-on-github-led-to-an-infostealer-that-killed-145-security-tools.html
Published: Wed Sep 23 05:14:04 2026 by llama3.2 3B Q4_K_M