A new malware campaign is hijacking search engine results to push a previously undocumented infostealer named Rapuncel, using fraudulent GitHub repositories that impersonate the LastPass Authenticator to target developers and IT professionals.

The attack vector combines social engineering with search engine optimization (SEO). The malicious GitHub repositories are crafted to rank highly in web searches for terms like "LastPass Authenticator," deceiving users into believing they have found an official or legitimate tool. The repos include convincing source code and documentation to appear authentic.

The primary threat is the payload delivered through these fake projects. Instructions and files within the repositories guide users to execute code that ultimately installs the Rapuncel infostealer. This malware is engineered to steal credentials and sensitive data from compromised systems, though researchers are still analyzing its full technical capabilities.

This campaign represents a strategic exploitation of trust, targeting the very professionals responsible for securing systems. By mimicking a known security tool, attackers aim to compromise software developers, DevOps engineers, and IT staff—individuals with elevated access to critical infrastructure.

The incident underscores a significant supply chain risk. Collaborative platforms like GitHub, due to their trusted reputation, are increasingly abused as distribution channels for malware. The SEO component broadens the danger, ensnaring victims who may not even be active GitHub users but are searching for tools online.

For development teams, this serves as a critical security alert. It reinforces the need for stringent vetting of any external code or tool. Teams should adopt a zero-trust approach, scrutinizing repositories before integration.

Recommended practices include: * Validating the publisher: Confirm the account is the verified, official organization with a legitimate history. * Assessing community trust: Look for organic activity through stars, forks, and issues from real users. * Inspecting the code: Check for obfuscation, suspicious external calls, or instructions to run unverified scripts. * Sourcing directly: Prioritize downloading software from the vendor's official website over third-party repositories.

According to the initial report, the campaign remains active. As of now, GitHub has not publicly detailed specific countermeasures against this SEO-based attack. This leaves the primary responsibility with users and organizations to exercise caution and verify software sources rigorously, even on established platforms.


新的惡意軟件攻擊活動正在劫持搜索引擎結果,推廣一種名為Rapuncel的前所未見數據竊取軟件。攻擊者使用偽造的GitHub儲存庫冒充LastPass Authenticator,以針對開發者及資訊科技專業人員。

攻擊向量結合了社會工程學與搜索引擎優化(SEO)技術。這些惡意GitHub儲存庫被精心設計,使其在「LastPass Authenticator」等關鍵詞的網絡搜索中排名靠前,欺騙用戶以為他們找到了官方或合法工具。儲存庫包含具說服力的源代碼及文件,以營造真實可信的表象。

主要威脅來自這些虛假項目所載的有效負荷。儲存庫內的說明及文件會引導用戶執行最終安裝Rapuncel數據竊取軟件的代碼。這種惡意軟件旨在從受感染系統中竊取認證憑證及敏感數據,不過研究人員仍在分析其完整技術能力。

此攻擊活動代表了對信任的策略性利用,專門針對負責保障系統安全的專業人員。透過模仿已知的安全工具,攻擊者旨在入侵軟件開發者、DevOps工程師及資訊科技人員——這些對關鍵基礎設施擁有高度存取權限的個體。

事件突顯了重大的供應鏈風險。GitHub等協作平台因其受信任的聲譽,正日益被濫用作惡意軟件的分發渠道。SEO成分擴大了危險範圍,甚至將可能並非活躍GitHub用戶、僅在網上搜索工具的受害者捲入其中。

對開發團隊而言,這是一個關鍵的安全警報。它加強了對任何外部代碼或工具進行嚴格審核的必要性。團隊應採用零信任方法,在整合前仔細檢查儲存庫。

建議的做法包括: * 驗證發布者: 確認該賬戶是經過驗證的官方組織,並具有合法歷史。 * 評估社區信任度: 查看來自真實用戶的自然互動,如星標(stars)、複製(forks)及議題(issues)。 * 檢查代碼: 檢查是否存在代碼混淆、可疑的外部調用或執行未經驗證腳本的指示。 * 直接獲取來源: 優先從供應商官方網站下載軟件,而非第三方儲存庫。

根據初步報告,該攻擊活動目前仍然活躍。截至現在,GitHub尚未公開說明針對此基於SEO攻擊的具體對策。這使得主要責任落在用戶及組織身上,即使在已建立的平台上,亦須謹慎行事並嚴格核實軟件來源。

新聞來源 / Original News Source