InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: LastPass warns about fake repositories that infect MacOS with Atomic Infostealer
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > LastPass warns about fake repositories that infect MacOS with Atomic Infostealer
Technology

LastPass warns about fake repositories that infect MacOS with Atomic Infostealer

September 20, 2025 2 Min Read
Share

LastPass warns of a continuous and widespread information steeler campaign targeting Apple MacOS users via fake GitHub repositories that distribute malware-covered programs pose as legitimate tools.

“In the case of LastPass, the fraudulent repository redirected potential victims to a repository that downloads Atomic Infostealer malware,” researchers Alex Cox, Mike Kosak and Stephanie Schneider said from LastPass’ Threat Intelligence, Mitigation and Escalization (Time) team.

Beyond the last pass, popular tools that impersonate campaigns include 1Password, Basecamp, Dropbox, Gemini, Hootsuite, Concepts, Obsidian, Robinhood, Salesloft, Sentinelone, Shopifififififififififififififififififififififide, Thunderbird, Tweetdeck, and more. All GIHUB repositories are designed to target MacOS systems.

The attack includes the use of search engine optimization (SEO) addiction, pushing a link to the malicious Github site above in Bing and Google search results, clicking the “Install LastPass on MacBook” button to download the program, and redirecting the GitHub page domain.

“Github pages are created with multiple Github usernames and appear to avoid Takedowns,” says LastPass.

The GitHub page is designed to take users to another domain that provides Clickfix-style instructions to copy and execute commands into a terminal app, and deploys Atomic Stealer malware.

Note that similar campaigns previously utilized previously malicious sponsored Google ads to distribute multi-stage droppers via fake GitHub repositories that can detect virtual machines or analytics environments.

In recent weeks, threat actors have been discovered to be leveraging public Github repositories to host malicious payloads and distribute them via Amadey, and have used a hanging committee that corresponds to the official Github repositories to redirect immature users to malicious programs.

See also  North Korean hackers use EtherHiding to hide malware inside blockchain smart contracts
Share This Article
Twitter Copy Link
Previous Article The strange ancient is the perfect sequel that sparked my witch's heart The strange ancient is the perfect sequel that sparked my witch’s heart
Next Article Thousands of people evacuated in Hong Kong after the discovery of a massive World War II bomb Thousands of people evacuated in Hong Kong after the discovery of a massive World War II bomb

You Might Also Like

North Korea-linked attackers exploit React2Shell to deploy new EtherRAT malware
Technology

North Korea-linked attackers exploit React2Shell to deploy new EtherRAT malware

7 Min Read
Malicious VSX extension 'SleepyDuck' uses Ethereum to keep command server alive
Technology

Malicious VSX extension ‘SleepyDuck’ uses Ethereum to keep command server alive

4 Min Read
India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud
Technology

India orders mobile phone manufacturers to pre-install Sanchar Saathi app to prevent wire fraud

4 Min Read
SonicWall fixes CVE-2025-40602 that is actively being exploited on SMA 100 appliances
Technology

SonicWall fixes CVE-2025-40602 that is actively being exploited on SMA 100 appliances

2 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?