# Fake LastPass Authenticator installer on GitHub loads a signed driver that stops 145 security processes

> Researchers say a fake LastPass Authenticator repository ranks in search results and installs a Windows driver that ends security tools before a password stealer runs.

FireAI Security & Research Team (HisnLabs) · Published 2026-09-30
Canonical: https://hisnlabs.com/en/news/fake-lastpass-authenticator-github-windows-driver

A fake LastPass Authenticator download hosted on GitHub installs a Windows kernel driver that ends security software and then runs a password stealer, researchers from LastPass and Delphos Labs said, [The Hacker News reported](https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html) on 17 September. The report states that no LastPass system was compromised: the attackers used only the name.

## Background

Attackers regularly copy the look of well-known software and rely on search engines to send people to the copy. Here the lure is a password-manager add-on, a tool whose users hold many stored logins, which raises the value of each victim [[1]](https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html).

## What the report describes

The fraudulent GitHub repository ranks high in search results. Its download button passes through several GitHub pages to an attacker-controlled server and delivers a ZIP file of roughly 128 to 148 MB that is padded with junk, which the report says can slip past scanners that limit file size. Inside are a renamed copy of a legitimate Microsoft debugging tool and a malicious library that Windows loads in its place [[1]](https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html).

The loader then raises itself to SYSTEM privileges through three separate methods and installs a kernel driver. The driver is a renamed component of a disk-encryption product and carries a Microsoft signature dated March 2023. According to the report, it ends 145 security-product processes from inside the kernel [[1]](https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html).

With defences down, a stealer collects saved credentials from more than 20 browsers, cryptocurrency wallets, Discord, Steam and Telegram sessions, and Windows Credential Manager, compresses them and sends them to the attacker. The report says the driver had zero detections on VirusTotal when checked in August, and that researchers attribute the loader to a paid crypter with moderate-to-high confidence [[1]](https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html).

> FireAI, the on-device firewall for macOS developed by HisnLabs, blocks unsigned apps in Paranoid mode and asks before a newly installed app connects. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for Mac users

This campaign is built for Windows: the driver, the debugging tool and the privilege escalation are Windows components. The report says researchers also saw a second fake repository for a macOS version of LastPass, but does not establish whether it caused any infections [[1]](https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html).

## Recommendations

1. Download password managers and their add-ons only from the vendor’s own website or an official app store, and type or bookmark the address instead of following a search result.
2. Treat a very large installer for a small utility as a warning sign.
3. If a machine ran this installer, the report advises treating it as compromised at kernel level: change saved passwords from a separate clean device and rebuild the system.
4. Review recent sign-in activity on important accounts.

## Relevance to FireAI

FireAI runs on macOS only and does not protect Windows machines. On a Mac, the same lure would still end with a stealer sending data out. A newly installed app with no rule triggers a connection prompt in Alert mode, and in [Paranoid mode](https://hisnlabs.com/en/docs/security-modes) unsigned apps are blocked. FireAI does not judge whether a download is genuine and does not remove anything already installed.

> Downloaded something that turned out to be a copy? FireAI shows which app connects out first. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

The report does not disclose how many people downloaded the installer, when infections happened or who runs the campaign. Its statements about zero detections and the crypter attribution come from the researchers, not from independent testing here.

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [The Hacker News, 17 September 2026: Fake LastPass Authenticator installer abuses a Microsoft-signed driver](https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html)
