← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 23, 2026 · 08:25via Security Affairs

Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools

Brief

Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer.

Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products using a driver that Microsoft itself had signed. That last part is the one worth sitting with.

LastPass’s Threat Intelligence, Mitigation, and Escalation team spotted the fake GitHub organization on August 13, 2026. It appeared high in search results for “LastPass Authenticator download” and used real LastPass logos and branding to look legitimate. The download page also displayed fake trust badges, including “VirusTotal Approved.”

The badges were meaningless and were simply there to make users feel safe enough to download the file.

Read more on Security Affairs