Malicious GitHub Installer Hijacks Windows Driver Signature to Disable Security Software Before Stealing Passwords
A counterfeit version of the LastPass Authenticator installer circulating on GitHub has been found to embed a Windows kernel driver that silently disables antivirus and endpoint detection tools before deploying a password‑stealing payload. Researchers from LastPass and the security firm Delphos Labs disclosed the technique on September 17, warning users that the malicious package appears legitimate at first glance but quickly compromises system defenses once executed.
The driver in question is signed with a Microsoft digital certificate, a detail that allows it to bypass many security checks that would normally block unsigned code from running at the kernel level. By leveraging a trusted signature, the malicious component can load into the operating system core, issue commands to deactivate security services, and create a window of opportunity for the subsequent credential‑theft module to operate undetected.
According to the joint analysis, the installer first drops the signed driver onto the victim's machine, triggers its activation, and then proceeds to terminate or suspend running antivirus and endpoint detection and response (EDR) solutions. Only after the protective layer is removed does the payload retrieve stored passwords and potentially exfiltrate them to a remote server controlled by the attacker. The entire chain is designed to be swift, reducing the chance that real‑time protection will intervene.
Security experts note that the use of a Microsoft‑signed driver for malicious purposes is not new, but the combination of a popular password‑manager’s brand name and a trusted code‑signing certificate raises the stakes. Users searching for legitimate authentication tools may be inadvertently drawn to the rogue repository, especially if the malicious release mimics the visual cues of an authentic installer. This underscores the broader challenge of supply‑chain attacks, where attackers exploit trusted distribution channels or reputable branding to increase credibility.
Both LastPass and Delphos Labs advise users to download software only from official vendor sites or verified app stores, and to verify the cryptographic hash of any installer before execution. Organizations are urged to enforce application whitelisting, maintain up‑to‑date endpoint protection, and monitor for unusual driver loading activity. As threat actors continue to weaponize legitimate signing credentials, the security community stresses the importance of layered defenses and vigilant software provenance checks to mitigate similar attacks in the future.
Comments (0)
Be the first to comment.
Join the discussion