Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

LastPass: GitHub hosts atomic stealer malware campaign

Mac users are being targeted by a GitHub malware campaign impersonating companies like LastPass and 1Password. Following fraudulent installation instructions installs Atomic Stealer (AMOS), which can steal credentials and financial data. Researchers advise downloading software only from official sources, avoiding unknown commands, and using antivirus and two-factor authentication.

byAytun Çelebi
September 25, 2025
in Cybersecurity

Cybersecurity researchers are warning Mac users about a malware campaign on GitHub. Attackers impersonate trusted companies, using fraudulent pages to distribute an infostealer that puts financial and personal data at risk.

The warning originates from LastPass Threat Intelligence, Mitigation, and Escalation (TIME) analysts. They first identified two fraudulent GitHub pages on September 16, 2025, under the username “modhopmduck476,” which purported to offer LastPass for Mac software. While these specific pages have been removed, the activity points to a broader, evolving campaign.

The attack chain is initiated when a user clicks a link labeled “Install LastPass on MacBook.” This triggers a redirect to hxxps://ahoastock825.github.io/.github/lastpass, followed by another to macprograms-pro.com/mac-git-2-download.html. On this final page, users are instructed to paste a command into their Mac’s terminal. The command uses a CURL request to fetch a base64-encoded URL, which decodes to bonoud.com/get3/install.sh. This script downloads an “Update” payload, installing malware into the system’s Temp directory.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

The malware payload is Atomic Stealer (AMOS), an infostealer active since April 2023 and used by financially motivated cybercriminals. This campaign extends beyond a single brand, with investigators linking it to fake repositories impersonating companies such as 1Password, Robinhood, Citibank, Docker, Shopify, and Basecamp. The primary objective is to steal sensitive user data, including credentials and financial information.

To enhance their reach and persistence, the attackers register multiple GitHub usernames to circumvent takedowns. They also employ Search Engine Optimization (SEO) to manipulate Google and Bing search results. This technique pushes the malicious links to a higher rank, increasing the probability that users searching for legitimate software will be directed to the fraudulent pages instead of official download sites.

LastPass stated it is “actively monitoring” the campaign, working on takedowns, and sharing indicators of compromise to help other organizations detect the threat. The attackers’ method highlights how quickly fraudulent repositories can be established on platforms like GitHub, taken down, and then recreated under new aliases. This cyclical activity poses a persistent protection challenge for such community-driven platforms.

Here are some recommended safety measures to mitigate these risks:

  • Downloading software only from verified, official sources.
  • Avoiding the execution of commands copied from unfamiliar websites.
  • Keeping macOS and all installed software fully updated.
  • Using antivirus software that provides ransomware protection.
  • Enabling regular system backups for data recovery.
  • Remaining skeptical of unexpected links, emails, and pop-ups.
  • Monitoring official advisories from software vendors.
  • Using strong, unique passwords combined with two-factor authentication.

Featured image credit

Tags: GithubLastPass

Related Posts

Microsoft uncovers Whisper Leak: A flaw that lets spies your AI chats

Microsoft uncovers Whisper Leak: A flaw that lets spies your AI chats

November 10, 2025
Google urges Gmail users to abandon passwords for passkeys

Google urges Gmail users to abandon passwords for passkeys

November 10, 2025
This Samsung Galaxy phone needs and immediate update

This Samsung Galaxy phone needs and immediate update

November 7, 2025
AMD confirms critical RDSEED flaw in Zen 5 CPUs

AMD confirms critical RDSEED flaw in Zen 5 CPUs

November 4, 2025
DOJ indicts DigitalMint and Sygnia employees for orchestrating ransomware attacks

DOJ indicts DigitalMint and Sygnia employees for orchestrating ransomware attacks

November 4, 2025
WhatsApp introduces passkeys for end-to-end encrypted chat backups

WhatsApp introduces passkeys for end-to-end encrypted chat backups

October 30, 2025

LATEST NEWS

Amazon Music tests “Fan Groups” to turn playlists into social spaces

IKEA unveils 21 new Matter-compatible smart home products

Play Store listings will soon show which apps kill your phone battery

Samsung and Apple finally connect: Siri can now control SmartThings devices

Firefox 145 launches with next-gen anti-fingerprinting protections

New Play Services update brings real-time video to SOS calls

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Glossary
    • Whitepapers
  • Newsletter
  • + More
    • Conversations
    • Events
    • About
      • About
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy Policy.