Malicious GitHub Repositories Disguised as Trusted Software Tools Spread New Rapuncel Stealer
Security researchers have identified a fresh malware operation that leverages search‑engine‑friendly GitHub pages to masquerade as legitimate software providers, distributing an undocumented information‑stealing program dubbed “Rapuncel.”
The campaign centers on repositories that appear to host authentic utilities such as the LastPass Authenticator, yet the downloadable binaries are laced with the Rapuncel payload. By optimizing repository descriptions and README files for popular keywords, the attackers increase the likelihood that users searching for trusted tools will encounter the counterfeit pages.
Rapuncel, which had not been documented in public threat‑intel feeds before this wave, is designed to harvest credentials, browser cookies, and other sensitive data from compromised machines. Early analysis indicates that the stealer can exfiltrate information to remote command‑and‑control servers, potentially facilitating further attacks such as credential stuffing or account takeover.
GitHub, a platform widely used by developers for open‑source collaboration, has become a recurring vector for malicious actors seeking credibility and free hosting. The use of SEO tactics represents an evolution of the strategy, allowing harmful code to surface alongside legitimate projects in search results. This method mirrors previous campaigns that impersonated popular utilities, but the focus on an authenticator app raises concerns given the growing reliance on two‑factor authentication for personal and corporate accounts.
Experts from the cybersecurity community, including those who originally reported the activity to BleepingComputer, advise users to verify the provenance of any code before downloading. Checking the publisher’s verified status, reviewing commit histories, and cross‑referencing official distribution channels can help avoid the trap. Organizations are also urged to enforce policies that restrict the installation of software from unapproved sources.
The discovery underscores the importance of continuous monitoring of open‑source ecosystems for abuse. As attackers refine their techniques, security teams may need to incorporate repository scanning into threat‑intelligence workflows and collaborate with platform providers to expedite takedown of fraudulent projects. Until broader mitigation measures are in place, vigilance remains the most effective defense against the Rapuncel stealer and similar threats.
Comments (0)
Be the first to comment.
Join the discussion