• Sources: primary
  • Summary: LastPass and Delphos Labs published the campaign report on 2026-09-18, covering SEO-optimized GitHub repositories that impersonate LastPass and at least 39 other companies to deliver a previously undocumented infostealer. The archives are inflated to as much as 148MB to evade scanning, and the installer is a renamed copy of the legitimate Visual Studio CoreCLR debugger vsdbg.exe configured to sideload a malicious vsdbg.dll. It drops the Alinubx.sys kernel driver, disguised as an NVIDIA component named nvfsflt64.sys and registered as the NvFsFilter service, which terminates a hardcoded list of 145 antivirus and EDR processes, and LastPass states the driver calls ObOpenObjectByPointer with AccessMode set to KernelMode, bypassing the user-mode access check and defeating Protected Process Light.
  • Why it matters: Developers searching for tooling are the targeted population and a GitHub repository is the lure, while the driver is signed through Microsoft's Windows Hardware Compatibility Publisher chain and absent from Microsoft's vulnerable driver blocklist, so the kill list runs with a valid signature on a default install.
  • Follow-up: Whether Microsoft adds Alinubx.sys to its vulnerable driver blocklist.

send feedback on this story