BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

LastPass Alerts macOS Users to GitHub Malware Targeting Popular Apps

Mac Malware Campaign Uses Fake GitHub Repositories and SEO Poisoning to Target Users with Atomic Stealer

  • Attackers are running a wide campaign that targets Apple macOS users with information-stealing Malware.
  • The campaign uses fake GitHub repositories to distribute malware disguised as trusted software tools.
  • Victims are led to download the Atomic Stealer malware through links appearing at the top of Bing and Google search results.
  • Multiple well-known apps, including LastPass, 1Password, and Dropbox, are being impersonated in this campaign.
  • Attackers use different GitHub accounts and SEO techniques to avoid detection and takedown efforts.

LastPass reported that a large-scale cyber campaign is currently targeting Apple macOS users. Attackers are deploying malware through fake GitHub repositories that appear to offer legitimate apps in order to steal information from computers.

- Advertisement -

The company’s Threat Intelligence, Mitigation, and Escalation (TIME) team confirmed on September 20, 2025, that victims who try to download LastPass for Mac are redirected through fraudulent repositories. These downloads actually install the Atomic Stealer malware, which is designed to harvest sensitive user information.

Researchers Alex Cox, Mike Kosak, and Stephanie Schneider of LastPass said the scheme is not limited to just their product. Other affected software names include 1Password, Basecamp, Dropbox, Gemini, Hootsuite, Notion, Obsidian, Robinhood, Salesloft, SentinelOne, Shopify, Thunderbird, and TweetDeck. According to the team, “The GitHub pages appear to be created by multiple GitHub usernames to get around takedowns.” Attackers use Search Engine Optimization (SEO) poisoning, making malicious links appear at the top of search results, which then lure users to click and download harmful software.

After reaching these fake GitHub repositories, victims are directed to another website. Here, the site offers step-by-step instructions that tell users to run a command through the Terminal app, which in turn launches the Atomic Stealer malware. This kind of attack exploits user trust in well-known apps and platforms.

Other recent attacks have used similar methods, such as fake Google Ads and deceptive GitHub repositories to deliver multi-stage malware that avoids detection and connects to remote servers for further actions, according to security researcher Dhiraj Mishra. In the past weeks, threat actors have also used public GitHub repositories to deliver malware via tools like Amadey, and have exploited weaknesses like “dangling commits” to redirect users to infected programs.

- Advertisement -

As this campaign continues, researchers warn Mac users to only download applications from official sources and to use caution when following search engine links that lead to unfamiliar sites.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

India: BRICS Pay aims for sovereignty, not de-dollarization

BRICS Pay focuses on financial sovereignty, not de-dollarization, according to BRICS International Chairman Pawan...

U.S. Senate Revises CLARITY Act Targeting DeFi Protocol Controls

Revised CLARITY Act directs regulators to assess non-decentralized finance trading protocol controllers under securities,...

SpaceX secures $13B ARR deal, eyes $100B year-end target

A new Hosting deal will add approximately $13 billion in annual recurring revenue starting...

Senate GOP Updated Clarity Act Targets Fake DeFi, Vote Set

Senate Republicans released an updated Clarity Act on Thursday targeting non-decentralized crypto trading protocols.The...

TSMC revenue hits record $16.3B, AI demand fuels 53% jump

TSMC reported a record August revenue of NT$514.8 billion ($16.3 billion), marking a 53.3%...

Must Read

8 Best Bitcoin Offshore Hosting Providers

In this blog post, we'll list the top 8 best bitcoin offshore hosting providers that accept Bitcoin and other cryptocurrencies.As Bitcoin continues to grow...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading