Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

LastPass: GitHub hosts atomic stealer malware campaign

Mac users are being targeted by a GitHub malware campaign impersonating companies like LastPass and 1Password. Following fraudulent installation instructions installs Atomic Stealer (AMOS), which can steal credentials and financial data. Researchers advise downloading software only from official sources, avoiding unknown commands, and using antivirus and two-factor authentication.

byAytun Çelebi
September 25, 2025
in Cybersecurity

Cybersecurity researchers are warning Mac users about a malware campaign on GitHub. Attackers impersonate trusted companies, using fraudulent pages to distribute an infostealer that puts financial and personal data at risk.

The warning originates from LastPass Threat Intelligence, Mitigation, and Escalation (TIME) analysts. They first identified two fraudulent GitHub pages on September 16, 2025, under the username “modhopmduck476,” which purported to offer LastPass for Mac software. While these specific pages have been removed, the activity points to a broader, evolving campaign.

The attack chain is initiated when a user clicks a link labeled “Install LastPass on MacBook.” This triggers a redirect to hxxps://ahoastock825.github.io/.github/lastpass, followed by another to macprograms-pro.com/mac-git-2-download.html. On this final page, users are instructed to paste a command into their Mac’s terminal. The command uses a CURL request to fetch a base64-encoded URL, which decodes to bonoud.com/get3/install.sh. This script downloads an “Update” payload, installing malware into the system’s Temp directory.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

The malware payload is Atomic Stealer (AMOS), an infostealer active since April 2023 and used by financially motivated cybercriminals. This campaign extends beyond a single brand, with investigators linking it to fake repositories impersonating companies such as 1Password, Robinhood, Citibank, Docker, Shopify, and Basecamp. The primary objective is to steal sensitive user data, including credentials and financial information.

To enhance their reach and persistence, the attackers register multiple GitHub usernames to circumvent takedowns. They also employ Search Engine Optimization (SEO) to manipulate Google and Bing search results. This technique pushes the malicious links to a higher rank, increasing the probability that users searching for legitimate software will be directed to the fraudulent pages instead of official download sites.

LastPass stated it is “actively monitoring” the campaign, working on takedowns, and sharing indicators of compromise to help other organizations detect the threat. The attackers’ method highlights how quickly fraudulent repositories can be established on platforms like GitHub, taken down, and then recreated under new aliases. This cyclical activity poses a persistent protection challenge for such community-driven platforms.

Here are some recommended safety measures to mitigate these risks:

  • Downloading software only from verified, official sources.
  • Avoiding the execution of commands copied from unfamiliar websites.
  • Keeping macOS and all installed software fully updated.
  • Using antivirus software that provides ransomware protection.
  • Enabling regular system backups for data recovery.
  • Remaining skeptical of unexpected links, emails, and pop-ups.
  • Monitoring official advisories from software vendors.
  • Using strong, unique passwords combined with two-factor authentication.

Featured image credit

Tags: GithubLastPass

Related Posts

Google: Hackers use EtherHiding on public blockchains

Google: Hackers use EtherHiding on public blockchains

October 17, 2025
Cisco’s Project CodeGuard brings OWASP-grade security to AI coding assistants

Cisco’s Project CodeGuard brings OWASP-grade security to AI coding assistants

October 17, 2025
Telegram channel hosts massive leak of DHS, FBI, and DOJ officials’ data

Telegram channel hosts massive leak of DHS, FBI, and DOJ officials’ data

October 17, 2025
WhatsApp Gold scam resurfaces nearly 10 years later

WhatsApp Gold scam resurfaces nearly 10 years later

October 17, 2025
Microsoft’s biggest-ever Patch Tuesday fixes 175 bugs

Microsoft’s biggest-ever Patch Tuesday fixes 175 bugs

October 15, 2025
Attackers used AI prompts to silently exfiltrate code from GitHub repositories

Attackers used AI prompts to silently exfiltrate code from GitHub repositories

October 15, 2025

LATEST NEWS

Twitch debuts live-shopping tech powered by Amazon Ads and e.l.f.

Amazon One Medical offers pay-per-visit kids’ virtual care

Spotify partners with record labels to build “responsible AI” music tools

Pinterest responds to “AI slop” backlash with new filtering tools

Meta Messenger desktop apps reach end of life in December

Reddit expands AI-powered search to five new languages

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.