Blog
Recent
LastPass Labs

Large-Scale Attack Targeting Macs via GitHub Pages Impersonating Companies to Attempt to Deliver Stealer Malware

Alex Cox, Mike Kosak & Stephanie SchneiderPublishedSeptember 18, 2025

The LastPass Threat Intelligence, Mitigation, and Escalation (TIME) team is tracking an ongoing, widespread infostealer campaign targeting Mac users through fraudulent GitHub repositories designed to trick potential victims into installing what is presented as various companies’ software for MacOS. In the case of LastPass, the fraudulent repositories redirected potential victims to a repository that downloads the Atomic infostealer malware. The threat actors are using Search Engine Optimization (SEO) to deliver links to their malicious sites at the top of search pages, including Bing and Google. This campaign appears to be targeting a range of companies, including tech companies, financial institutions, password managers, and more. Further information on the targeted companies can be found in the Indicators of Compromise (IoCs) at the end of the blog.

We are writing this blog post to raise awareness of the campaign and protect our customers while we continue to actively pursue takedown and disruption efforts, and to also share indicators of compromise (IoCs) to help other security teams detect cyber threats. This excellent blog post by Dhiraj Mishra describes a similar campaign targeting another software that bears many of the same hallmarks as the campaign we are addressing here. We are actively monitoring this campaign and will update our blog post with any new information.

Malicious GitHub Pages Claiming to Offer LastPass Removed

LastPass tracked two fraudulent GitHub sites targeting our customers; these sites were immediately submitted for takedown and are now inactive.

Screen Capture of SEO-driven Referral to Malicious Software

Campaign Details

  • Two GitHub pages impersonating LastPass were posted to GitHub by the user “modhopmduck476” on 16 September. Both pages included links allegedly to “Install LastPass on MacBook” that redirected to the same page: hxxps://ahoastock825[.]github[.]io/.github/lastpass.
    • Notably, the GitHub pages appear to be created by multiple GitHub usernames to get around takedowns.
    • The GitHub page headlines include “name of company” and Mac-related terminology (i.e. MacOS, Mac, Premium on Macbook) since that’s what they are targeting.

Screen Capture of the LastPass Impersonation Page

  • This site then redirects to the URL “macprograms-pro[.]com/mac-git-2-download.html”.
  • That site instructs users to copy and paste the following command into their Mac’s terminal:

Screen Capture of the Secondary Site

  • The command then conducts a CURL request to a base64 encoded URL which decodes to: bonoud[.]com/get3/install.sh
  • This site then delivers the following payload:

  • This in turn downloads the “Update” payload to the Temp directory. The Update payload is in fact Atomic stealer (aka AMOS malware). Atomic stealer has been available since at least April 2023. The malware has previously been associated with financially motivated cybercrime groups.
  • LastPass will continue to monitor this campaign and provide updates as warranted.

Indicators of Compromise (IoCs)

URLs:

  • github[.]com/lastpass-on-macbook
  • github[.]com/LastPass-on-MacBook/lastpass-premium-mac-download
  • ahoastock825[.]github[.]io/.github/lastpass
  • macprograms-pro[.]com/mac-git-2-download.html
  • bonoud[.]com/get3/install.sh
  • bonoud[.]com/get3/update
  • github[.]com/Zengo-Wallet-Desktop-App-on-Macbook
  • github[.]com/1password-on-Macbook-Desktop
  • github[.]com/1Password-Premium-on-MacBook
  • github[.]com/ActiveCampaign-Desktop-on-Mac
  • github[.]com/ActiveCampaign-MacBook-Desktop-App
  • github[.]com/After-Effects-Desktop-on-Mac
  • github[.]com/Audacity-on-Macbook
  • github[.]com/Auphonic-Desktop-on-Mac
  • github[.]com/Basecamp-App-macOS-Installation
  • github[.]com/BetterSnapTool-on-MacBook
  • github[.]com/Biteable-Desktop-on-Mac
  • github[.]com/Bitpanda-on-MacBook
  • github[.]com/Bitsgap-Download-Mac
  • github[.]com/Blog2Social-Desktop-on-Mac
  • github[.]com/Blue-Wallet-Desktop-on-Mac
  • github[.]com/Bonkbot-On-Macbook
  • github[.]com/Carbon-Copy-Cloner-on-MacBook
  • github[.]com/Carbon-Copy-Cloner-on-MacBook
  • github[.]com/Charles-Schwab-Desktop-on-MacBook
  • github[.]com/Citibank-on-MacBook-Desktop-App
  • github[.]com/CMC-Markets-on-MacBook
  • github[.]com/Confluence-on-MacBook
  • github[.]com/Coolors-Desktop-on-Mac
  • github[.]com/DaVinci-Resolve-on-MacBook
  • github[.]com/DefiLlama-on-Mac-Desktop-App
  • github[.]com/Desktop-Clockology-Mac-Os
  • github[.]com/Desygner-Desktop-on-Mac
  • github[.]com/Docker-MacBook-Desktop-App
  • github[.]com/Dropbox-on-Macbook
  • github[.]com/EigenLayer-Desktop-App-on-MacBook
  • github[.]com/EigenLayer-Desktop-App-on-MacBook
  • github[.]com/EigenLayer-Desktop-App-on-MacBook
  • github[.]com/E-TRADE-on-MacBook
  • github[.]com/Fidelity-on-MacBook
  • github[.]com/Fliki-Desktop-on-Mac
  • github[.]com/Freqtrade-Bot-on-Macbook
  • github[.]com/Freshworks-App-on-MacBook
  • github[.]com/Gemini-on-MacBook
  • github[.]com/GMGN-AI-Desktop-App-On-MacBook
  • github[.]com/Gunbot-Desktop-on-Macbook
  • github[.]com/Hemingway-Editor-Desktop-on-Mac
  • github[.]com/HeyGen-Desktop-on-Mac
  • github[.]com/Hootsuite-MacBook-Desktop-App
  • github[.]com/HTX-App-on-MacBook-Download
  • github[.]com/Hypertracker-Desktop-on-Mac
  • github[.]com/IRS-Desktop-App-on-Macbook
  • github[.]com/KeyBank-on-Mac-Desktop
  • github[.]com/Lightstream-Desktop-on-Mac
  • github[.]com/Loopback-on-MacBook
  • github[.]com/Maestro-Bot-Desktop-on-Macbook
  • github[.]com/Melon-Desktop-on-Mac
  • github[.]com/Metatrader-5-Download-on-Mac
  • github[.]com/Metricool-Desktop-on-Mac
  • github[.]com/Mixpanel-on-MacBook
  • github[.]com/Mp3tag-Desktop-on-Mac
  • github[.]com/Mural-App-on-MacBook
  • github[.]com/NFT-Creator-on-Macbook
  • github[.]com/NotchNook-Download-on-Mac
  • github[.]com/Notion-Download-on-Mac
  • github[.]com/Obsidian-on-Macbook
  • github[.]com/Onlypult-Desktop-on-Mac
  • github[.]com/Pendle-Finance-Desktop-on-Mac
  • github[.]com/Pepperstone-on-MacBook
  • github[.]com/Pipedrive-on-Mac-Desktop-App
  • github[.]com/Plus500-on-MacBook
  • github[.]com/Privnote-on-MacBook
  • github[.]com/ProWritingAid-Desktop-on-Mac
  • github[.]com/Publer-Desktop-on-Mac
  • github[.]com/Raycast-App-on-Mac
  • github[.]com/Raycast-Download-on-Mac
  • github[.]com/Reaper-Desktop-on-Mac
  • github[.]com/RecurPost-Desktop-on-Mac
  • github[.]com/Renderforest-Desktop-on-Mac
  • github[.]com/Rippling-App-on-MacBook
  • github[.]com/Riverside-fm-Desktop-on-Mac
  • github[.]com/Robinhood-Desktop-on-MacBook
  • github[.]com/Rug-AI-on-Macbook
  • github[.]com/Sage-Intacct-on-Mac-Desktop-App
  • github[.]com/Salesloft-on-MacBook
  • github[.]com/SentinelOne-on-MacBook
  • github[.]com/Shippo-on-MacBook
  • github[.]com/Shopify-on-MacBook
  • github[.]com/SocialPilot-Desktop-on-Mac
  • github[.]com/Soundtrap-Desktop-on-Mac
  • github[.]com/StreamYard-Desktop-on-Mac
  • github[.]com/SurferSEO-Desktop-on-Mac
  • github[.]com/Thunderbird-on-MacBook
  • github[.]com/TweetDeck-Desktop-on-Mac
  • github[.]com/Uphold-App-on-MacBook
  • github[.]com/Uphold-App-on-MacBook
  • github[.]com/Veeva-CRM-on-MacBook
  • github[.]com/Viraltag-Desktop-on-Mac
  • github[.]com/VSCO-Desktop-on-Mac
  • github[.]com/Vyond-Desktop-on-Mac
  • github[.]com/Webull-on-Macbook
  • github[.]com/Xai-Games-App-on-MacBook
  • github[.]com/XSplit-Desktop-on-Mac
  • github[.]com/Zealy-Desktop-on-MacBook
  • github[.]com/Zencastr-Desktop-on-Mac
  • github[.]com/Zenefits-on-MacBook
  • github[.]com/Zotero-7-on-MacBook

SHA256 Hash:

  • e52dd70113d1c6eb9a09eafa0a7e7bcf1da816849f47ebcdc66ec9671eb9b350 (Atomic Stealer)
Share this post via:share on linkedinshare on xshare on facebooksend an email