- Sources: primary
- Summary: LastPass and Delphos Labs published the campaign report on 2026-09-18, covering SEO-optimized GitHub repositories that impersonate LastPass and at least 39 other companies to deliver a previously undocumented infostealer. The archives are inflated to as much as 148MB to evade scanning, and the installer is a renamed copy of the legitimate Visual Studio CoreCLR debugger
vsdbg.exe configured to sideload a malicious vsdbg.dll. It drops the Alinubx.sys kernel driver, disguised as an NVIDIA component named nvfsflt64.sys and registered as the NvFsFilter service, which terminates a hardcoded list of 145 antivirus and EDR processes, and LastPass states the driver calls ObOpenObjectByPointer with AccessMode set to KernelMode, bypassing the user-mode access check and defeating Protected Process Light. - Why it matters: Developers searching for tooling are the targeted population and a GitHub repository is the lure, while the driver is signed through Microsoft's Windows Hardware Compatibility Publisher chain and absent from Microsoft's vulnerable driver blocklist, so the kill list runs with a valid signature on a default install.
- Follow-up: Whether Microsoft adds
Alinubx.sys to its vulnerable driver blocklist.
send feedback on this story