Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

LastPass: GitHub hosts atomic stealer malware campaign

Mac users are being targeted by a GitHub malware campaign impersonating companies like LastPass and 1Password. Following fraudulent installation instructions installs Atomic Stealer (AMOS), which can steal credentials and financial data. Researchers advise downloading software only from official sources, avoiding unknown commands, and using antivirus and two-factor authentication.

byAytun Çelebi
September 25, 2025
in Cybersecurity
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

Cybersecurity researchers are warning Mac users about a malware campaign on GitHub. Attackers impersonate trusted companies, using fraudulent pages to distribute an infostealer that puts financial and personal data at risk.

The warning originates from LastPass Threat Intelligence, Mitigation, and Escalation (TIME) analysts. They first identified two fraudulent GitHub pages on September 16, 2025, under the username “modhopmduck476,” which purported to offer LastPass for Mac software. While these specific pages have been removed, the activity points to a broader, evolving campaign.

The attack chain is initiated when a user clicks a link labeled “Install LastPass on MacBook.” This triggers a redirect to hxxps://ahoastock825.github.io/.github/lastpass, followed by another to macprograms-pro.com/mac-git-2-download.html. On this final page, users are instructed to paste a command into their Mac’s terminal. The command uses a CURL request to fetch a base64-encoded URL, which decodes to bonoud.com/get3/install.sh. This script downloads an “Update” payload, installing malware into the system’s Temp directory.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

The malware payload is Atomic Stealer (AMOS), an infostealer active since April 2023 and used by financially motivated cybercriminals. This campaign extends beyond a single brand, with investigators linking it to fake repositories impersonating companies such as 1Password, Robinhood, Citibank, Docker, Shopify, and Basecamp. The primary objective is to steal sensitive user data, including credentials and financial information.

To enhance their reach and persistence, the attackers register multiple GitHub usernames to circumvent takedowns. They also employ Search Engine Optimization (SEO) to manipulate Google and Bing search results. This technique pushes the malicious links to a higher rank, increasing the probability that users searching for legitimate software will be directed to the fraudulent pages instead of official download sites.

LastPass stated it is “actively monitoring” the campaign, working on takedowns, and sharing indicators of compromise to help other organizations detect the threat. The attackers’ method highlights how quickly fraudulent repositories can be established on platforms like GitHub, taken down, and then recreated under new aliases. This cyclical activity poses a persistent protection challenge for such community-driven platforms.

Here are some recommended safety measures to mitigate these risks:

  • Downloading software only from verified, official sources.
  • Avoiding the execution of commands copied from unfamiliar websites.
  • Keeping macOS and all installed software fully updated.
  • Using antivirus software that provides ransomware protection.
  • Enabling regular system backups for data recovery.
  • Remaining skeptical of unexpected links, emails, and pop-ups.
  • Monitoring official advisories from software vendors.
  • Using strong, unique passwords combined with two-factor authentication.

Featured image credit

Tags: GithubLastPass

Related Posts

Why secure software delivery depends on better release management

Why secure software delivery depends on better release management

June 3, 2026
Popular Codex package caught exfiltrating authentication credentials

Popular Codex package caught exfiltrating authentication credentials

June 2, 2026
GTA V cheat service Atlas Menu hacked, exposing 64,000 accounts

GTA V cheat service Atlas Menu hacked, exposing 64,000 accounts

June 2, 2026
Meta patches AI flaw that enabled Instagram account takeovers

Meta patches AI flaw that enabled Instagram account takeovers

June 2, 2026
GitHub confirms breach after hackers steal 3,800 code repositories

GitHub confirms breach after hackers steal 3,800 code repositories

May 20, 2026
Myhtos reportedly helped researchers uncover macOS exploit

Myhtos reportedly helped researchers uncover macOS exploit

May 19, 2026

LATEST NEWS

Amazon adds AI-generated product previews to search results

Meta launches AI business agents on WhatsApp, Instagram and Messenger

Nintendo will release a repair-friendly Switch 2 in Europe

Google rolls out Ask Gemini in Drive to eligible Workspace users

Google Wallet to add digital IDs from select EU countries this summer

Why Telegram Mini Apps have become the optimal ecosystem for launching AI SaaS products

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Roboto AI

Pickaxe

Pfpmaker

MindPal

Syllaby

ScreenApp

FinanceBrain

GitHub Spark

Hints

VisionStory AI

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.