Cyber AttacksMalware

LastPass warns of macOS Atomic Infostealer via Fake GitHub Repos

0

LastPass has issued a warning about an active, large-scale campaign that uses fake GitHub repositories to deliver an information-stealing malware family called Atomic to macOS users. The repositories pose as trusted utilities, tricking victims into downloading malware-laced installers that masquerade as legitimate apps.

Researchers Alex Cox, Mike Kosak, and Stephanie Schneider of the LastPass Threat Intelligence, Mitigation, and Escalation (TIME) team explained that the fraudulent repositories often redirect users to a secondary repo that installs the Atomic infostealer. 

Attackers impersonate many well-known tools—examples observed include 1Password, Basecamp, Dropbox, Gemini, Hootsuite, Notion, Obsidian, Robinhood, Salesloft, SentinelOne, Shopify, Thunderbird, and TweetDeck—specifically targeting macOS users.

The campaign relies on SEO poisoning to push malicious GitHub links to the top of Bing and Google search results. Victims are then instructed to click an attractive “Install LastPass on MacBook” (or similar) button, which redirects them to a GitHub Pages domain. Those pages—created under multiple GitHub accounts to evade takedowns—guide users through a ClickFix-style process that asks them to copy and paste a command into the Terminal app. Running that command deploys the Atomic Stealer on the victim’s machine.

Security researchers note this technique is not new. Attackers have previously abused sponsored Google Ads and bogus GitHub repositories to distribute multi-stage droppers that detect virtual machines or analysis environments, then decode and execute system commands to contact remote servers.

 In recent weeks, public GitHub repositories have also been abused to host payloads delivered via Amadey, and threat actors have used dangling commits on legitimate repositories to redirect users to malicious code.cyber s

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

ShinyHunters steal 1.5B salesforce records via Drift OAuth Breach

Previous article

Massive AWS Outage crashes major sites offline

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *