Malware Campaign Uses Fake GitHub Repositories to Spread Rapuncel Infostealer and Disable Antivirus Software
A sophisticated malware campaign has been uncovered, using fake GitHub repositories to impersonate well-known software firms and push a previously undocumented information stealer called Rapuncel. LastPass and Delphos Labs have discovered that the campaign targets at least 40 companies, including password manager brands, and delivers a Microsoft-signed kernel driver capable of disabling 145 antivirus and endpoint detection and response (EDR) products.
The attack chain begins when victims search for legitimate software on GitHub and follow links to fake repositories. Clicking download buttons triggers a series of redirections before reaching payload-delivery servers, where victims receive ZIP archives with inflated sizes up to 148MB, designed to evade security scans. Inside these archives lies the Rapuncel infostealer, which is installed using a legitimate Microsoft Visual Studio CoreCLR Debugger installer renamed and configured to sideload a malicious DLL.
The kernel driver, disguised as an NVIDIA component named ‘nvfsflt64.sys’, registers as the NvFsFilter service and acts as an EDR killer by terminating processes that match its hardcoded list of 145 antivirus and EDR products. This driver bypasses Protected Process Light (PPL) protections relied upon by many security software solutions, rendering them ineffective against this malware.
Once security software is terminated, the Rapuncel infostealer begins stealing sensitive information from the infected device. It collects credentials stored in 25 web browsers, data from 30 cryptocurrency wallets, session credentials for popular platforms like Discord and Steam, Windows Credential Manager contents, documents containing specific keywords, screenshots from connected monitors, and detailed system information.
To bypass Google’s app-bound encryption protection on Chrome and Edge, Rapuncel injects a helper DLL into the app and invokes its own Elevation Service. The stolen information is compressed and uploaded to an external endpoint using HTTP-formatted requests over raw TCP. Notably, Rapuncel persists across reboots via a Windows service, making it difficult for security tools to reactivate.
The similarities between Rapuncel and BoryptGrab have been noted by researchers, while its loader was built with the Cruciferra PUROSANGUE crypter. This campaign serves as a stark reminder of the ongoing threat landscape and the importance of vigilance in cybersecurity.
To protect yourself from such attacks, it is essential to download software only from official websites and avoid dubious GitHub repositories. Be cautious when searching for software online, and skip or block promoted results on Google Search.
Source: Bleeping Computer — 2026-09-18