The download page looked like GitHub. That was the point.
GitHub is where real software lives, which is exactly why a fake page there works so well.
LastPass and Delphos Labs published their findings this week on a campaign that has been running since at least 13 August. Someone built repositories impersonating LastPass Authenticator and around 39 other well known companies, tuned them to rank in search results, and waited. Click the download button and you are bounced through a chain of redirects to a server that hands over a ZIP file padded out to as much as 148MB, big enough that plenty of scanners will not look inside it. What is in the archive is a renamed copy of a genuine Microsoft debugging tool, vsdbg.exe, sitting next to a malicious DLL it loads without asking.
Two things come out of that. The first is a new password stealer the researchers named Rapuncel, which empties saved credentials out of more than 25 browsers, goes after about 30 cryptocurrency wallets, takes Discord, Steam and Telegram session tokens and the contents of Windows Credential Manager, and grabs screenshots on the way past. The second is worse: a kernel driver called Alinubx.sys that carries a valid Microsoft signature and can shut down 145 different antivirus and security products. The protection is not bypassed, it is turned off.
The habit that beats this is dull and it works: get software from the maker's own website, typed in yourself, not from a search result and not from a repository you have never heard of. Anyone who did run one of these installers should change their passwords from a different device entirely. Tendvane's app updates go through winget, which pulls from official publisher sources rather than from whatever is ranking highest today.