An authenticator belongs on a phone so a login box can get a six-digit code. When you search for a download on a computer, the thing you think you are handing over is one install, one official brand, and a program that only mints codes. Mail passwords the browser already remembers, game sessions, and wallet files look unrelated to “just one more authenticator.” On 17 September 2026, LastPass and Delphos Labs split that assumption. A GitHub product page sitting near the top of search can borrow the brand without going through the official stores. After Windows has run that unofficial installer, what gets read is not the code itself. It is the passwords and sessions already stored on that machine.

An earlier piece covered what hashes, sessions, and image text still keep after a password screenshot goes to Gyazo. That was a picture you chose to upload. This piece asks a different question: you never pasted a password into a chat box, and you never uploaded a screenshot — you only installed an “authenticator” from search. Can the passwords, sessions, and wallets saved on this computer still be read? If a key moves to a one-time link, the shape is still s.html?id=…#…. Create and read need no account. MyPassGen tools open without sign-up. This page does not unpack an installer and does not describe how a program runs. It lines up the scope already written in The Hacker News account of the 17 September joint note, the BleepingComputer report of 18 September, and the SecurityWeek report of 21 September, plus the download source you can check yourself.

Separate two facts first

“LastPass systems and customer vaults were not breached” covers the cloud side. It does not keep saved browser passwords safe on a Windows PC that already ran an unofficial installer from search. Change passwords from a device you can confirm is clean. Do not let “the company was not hacked” stand in for “which passwords this machine saved, and which sessions are still alive.” Do not open an installer of unknown origin just to compare.

A search result is not the official authenticator

LastPass describes Authenticator as a free iOS and Android app: the Apple store, Google Play, or the path that starts at lastpass.com and walks into those stores. It mints standard TOTP codes, and on supported logins it can approve with a push. The official path is not “search GitHub for a repository and download a Windows installer.” A result near the top of search proves that the words and the page look familiar. It does not prove a signature, and it does not prove a store review.

That is a different road from “did this page upload the password I am generating as business data.” On the MyPassGen generator you can open the browser Network panel and check that plaintext was not sent as business data. An installer you reached from search follows that page’s own redirects and that page’s own download. The joint note says fake product pages rank for searches such as “LastPass Authenticator download.” The download click walks through several more hops and lands on an archive the operators control. Those archives were padded up to 148 MB so some tools that skip files by size would pass them. A large file is not evidence of a complete official installer.

In the clipboard piece, the password left the generator page and entered the system clipboard. A browser “save password” leaves the login box and enters browser storage on this machine. You do not have to press Copy for the password to be local already. Once an unofficial installer has run on this Windows PC, that is the layer it reads — not whether you pasted the password into chat. Handing an unredacted password to browser save is the same class of problem as writing it into an email body: the other side sees a copy you chose to leave, as in what Sent, forwards, and phone previews still keep after a temporary password goes into an email.

The numbers in the 17 September note

LastPass’s threat team and Delphos Labs published the joint note on 17 September 2026. The Hacker News retold it on 21 September. BleepingComputer wrote the scope on 18 September, and SecurityWeek on 21 September. Hold three sentences first. Official systems, services, and customer vaults were not breached; the brand name was borrowed. The real authenticator comes from lastpass.com and the official app stores, not from GitHub. If this Windows PC already ran that unofficial installer, treat local saved passwords and sessions as already read.

The campaign was identified on 13 August. LastPass wrote that the same kit impersonated at least 40 brands — the password-manager lure, plus at least 39 other companies. A second fake page for a macOS LastPass product was taken down before researchers could inspect it. The joint note calls this unofficial installer Rapuncel and says it collects saved credentials from more than 25 browsers, data from about 30 cryptocurrency wallets, login sessions for Discord, Steam, and Telegram, the contents of Windows Credential Manager, documents whose names contain password, seed, wallet, or recovery, and a screenshot of every connected display. No infection count was published.

The official line on “was the vault dragged out” is hard: no. What stays in doubt is your own download path. Remembering that you installed from a phone store, and finding a 100-plus-megabyte archive in this Windows Downloads folder, are not the same event. The word “LastPass” in a headline cannot answer “which link did I open.”

Saved browser passwords were already on this PC

Browser “save password” keeps the site, the account, and the password in local configuration so the next login can fill itself. You do not have to press Copy. The password has already left the login box and entered this computer. The joint note puts “saved credentials from more than two dozen browsers” on the collection list. That layer is not the one password you are generating now. It is the whole list of Save clicks from the last months and years.

Reuse turns one list into several doors. If mail, a drive, and a code host share a similar password, whoever reads the saved-password list does not have to guess what you used elsewhere. Checking this machine against a common weak-password list can show a hit on a public list. It cannot show whether this machine was read. See how a local leak-list check differs from a web-wide password lookup. What needs rotation is the batch this Windows browser once saved, not the glance that says “I already uninstalled that package.”

Chrome and Edge later added local protection meant to stop someone from simply copying the saved-password file. The joint note still includes saved items from those browsers in the collection scope. For a person who can check on the spot, the difference is not the name of an algorithm. It is whether the password still sits in autofill on a machine that may already have been read. If you can avoid saving a production password in the browser, do not hand a master password to autofill. When you must save one, count “if this computer is read, the whole list leaves” as leftover — not only “I never pressed Copy.”

Sessions, wallets, and screenshots are a second layer

A Discord, Steam, or Telegram login session is proof that “this is already me.” Changing the password in the login box does not stop a session that is still alive. The earlier piece on AI tokens quoted Okta calling an unexpired session a skeleton key. See who can still walk into the AI session in your browser after you change the password and MFA. The joint note lists session credentials for those three services on their own. Changing only the password, without opening each service’s signed-in device list, leaves that layer in place.

Wallet files and documents whose names contain seed or recovery are another path. The browser saves site passwords. A recovery phrase or a wallet backup on the desktop often sits in the documents folder as an ordinary file. The joint note puts “about thirty wallets” and those filenames on the same list. A screenshot takes the pixels that were on screen at the time — a full one-time URL in the address bar, a visible password-manager result, a recovery phrase you just opened. For a screenshot, those are the same kind of picture. How pixels linger in a local PNG and a meeting recording is in who can still see a password — and the key after # — in a screenshot or screen share.

Windows Credential Manager is a third layer. Wi-Fi, apps, and saved logins that the system itself stores do not always appear in the browser’s saved list, and they are still on this machine. The joint note puts that store next to browser credentials. Clearing only Chrome’s saved passwords does not empty this layer. Do not let the three stand in for each other. Changing a site password, revoking a chat session, and moving a wallet backup off this machine are three separate jobs.

Changing passwords on the same PC is not a clean bill

The note’s instruction for anyone who already ran the unofficial installer is blunt. Treat every saved browser password on this machine, every wallet file, every Discord, Steam, and Telegram session, and the contents of Credential Manager as already gone. Change passwords from another device you can confirm is clean. Do not open those sites on this machine and change them here. The note also says collection can continue after a reboot. Turning security software off and back on does not stop the next read. If you can reinstall the system, or if someone can do a kernel-level check, treat the machine as already read. Do not stop at removing one icon.

“I already deleted that installer” and “I changed the mail password on this computer” are not a clearance. The test is whether you are still signing into accounts you need to protect from the same Windows PC. An untouched official vault only means the LastPass cloud side was not the source. Passwords you saved in your own browser, and passwords you reused, still need rotation as copies that have already left.

Do not open the download page in search again “to see if it is the same installer,” and do not run a file of unknown origin on this machine to compare. What you can look at on the spot is whether Downloads holds a large archive you do not remember coming from an official store, and whether you walked in from lastpass.com or from a search result that led to GitHub. The path matches an official store before you can say “I installed the authenticator.” If the path does not match, treat the saved list on this machine as already gone.

Side by side: the store app and the unofficial installer

The same test password that once lived in the browser can leave along at least five paths of “who can still read it.” The difference is not a brand slogan. It is whether you opened a store or a search result, and which device you were on when you changed the password.

What you did What is still on this machine What the joint note already names
Installed the authenticator on a phone from the official store only TOTP on the phone; the computer’s saved-password list is still there None from this path (the note says official systems and vaults were not breached)
Downloaded a Windows installer from search and ran it The saved list, Credential Manager, and wallet files are still on disk Treat credentials from 25-plus browsers, sessions, wallets, and screenshots as collected
Deleted the installer, then changed passwords on this PC The new password enters an environment that may already have been read The note says use a clean device; reads can continue after a reboot
Changed the site password and never opened signed-in devices Unrelated to the session list Discord, Steam, and Telegram sessions can still be valid
Never saved the password in the browser; the handoff used a one-time link with the channel split The test file can be deleted A full credential is not in the saved list; both halves are required to decrypt

Do not mix the fifth row with the first four. Saving a complete s.html?id=…#… as a browser bookmark, or copying it onto this possibly read computer, still lets a session or a screenshot take the whole credential. The host that stores ciphertext cannot see the key. Split the id and the key, and a full-text search cannot find a link that opens. The full link still has to be kept like the password itself. Encrypting a file on this device before you sync it is a file job. Once the saved-password list has been read, adding a .lock later does not pull plaintext passwords back.

Check on the spot

These steps do not depend on a brand promise. Use a test password that will not sign into a real work account, for example a local line that only says orange-lake-7. Do not practice with a master password you still use, a production API key, a real wallet, or a live one-time link. Do not run an installer from search just to check.

  1. Recall where you installed LastPass Authenticator. The official path is the Apple store, Google Play, or a walk from lastpass.com into those two stores. Official copy describes a phone app, not a Windows installer on GitHub. If what you opened was a repository page in search results, write that down. A logo on the page is not a store.
  2. Open Downloads on this Windows PC and sort by date. Look for a very large archive since mid-August whose name looks like an authenticator or like LastPass. The joint note described packages padded to 148 MB. If you have one, and you cannot match it to an official store, treat the saved list on this machine as possibly already gone. Do not extract it. Do not click it again.
  3. If you are sure you ran an unofficial installer: stop signing into accounts you need to protect from this computer. Switch to another device you can confirm is clean — the official phone app, or another computer that never downloaded that package — and change passwords there. MyPassGen’s password generator random mode is 6–128 characters, default 16, and it warns below 8. It opens without an account, and the result is not uploaded as business data. For a password you reused, the strength check compares it on this device with a common weak-password list. A hit proves a public-list match. It does not prove this machine was read.
  4. On the clean device, open the signed-in device or session list for Discord, Steam, and Telegram, and revoke sessions you do not recognize. Changing only the password, without looking at that list, replaces the door key and leaves the badge that was already issued. Do the same “signed-in devices” pass for mail, drives, and code hosts.
  5. Do not open wallet files, or documents whose names contain a recovery phrase, on the suspect computer. If you can check balances and transfers from the official wallet app on a clean device, look first for actions you did not take. A seed phrase that once sat in the documents folder on this machine should be treated as already copied. Do not stop at changing one website password.
  6. Create a separate MyPassGen one-time link, write the same test password, set expiry to 24 hours, and leave reads at 1. In chat or a ticket, paste only the s.html?id=… in front of the hash. Say the key by phone or in person. It opens without an account. The recipient should see an incomplete link when they have only the id. Both halves are required to decrypt. After the read, overwrite the clipboard. Do not store an address that contains # in a browser profile that syncs, and do not leave the result page full-screen on this computer.

On a work computer, add half a step: ask which official list software must be installed from, and whether a repository from search is allowed onto the download allowlist. MyPassGen will not decide for you whether a given machine was read. The check is the download source you just confirmed, and the session list on a clean device.

If you have to hand off a key, split it

For a one-to-one handoff the other person can open now, do not write the password into a place that will enter a browser saved list, this computer’s documents folder, or the pixels of a screenshot. Generate it on this device, then wrap it in a one-time link. On create, the browser encrypts with AES-256-GCM. A single note caps at 32 KB. Reads default to 1 and cap at 10. Expiry can be 1 hour, 24 hours, 7 days, or count-only with no TTL. The server parks ciphertext only. The key sits after # in the URL, so access logs and Referer do not see that slice. A saved-password list that has already been read, and a full-screen capture, can still see it. Do not hand the full link to autofill, and do not leave the result page on the desktop.

When a repo or a ticket still needs an entry point, split the channel. The file carries only the owner, the id, and the sentence “key by phone.” A call, an in-person handoff, or a different messenger account carries only the slice after #. Neither half decrypts alone. That is a usage pattern, not a product default. The create page still emits one full link, which is convenient for a one-to-one send. On a channel that draws preview cards, run a test link first and see whether the preview counts a read, as in if you paste a one-time link into Slack or WeChat, does the preview burn it first. Redact an error or a config excerpt in Clean URL / redaction before you decide whether it still needs to go into chat.

A key pack or export larger than 32 KB does not belong on a one-time text link. Use the file encryption box: streaming AES-256-GCM in the browser, one file up to 5 GB, output .lock / .enc, passphrase sent separately. Encrypt on this device first, then sync; the other side should see ciphertext only. Handing an unredacted password to browser save is the same class of problem as pushing an unencrypted certificate bundle into a drive: the copy that proves “this is me” or “this is the key” left the window you thought was only installing an authenticator. How to check, in the browser, that plaintext was not uploaded as business data is in how to check in the browser that plaintext was not uploaded.

After you have checked “did I install from the official store or from search,” “should this Windows PC still be used to change passwords,” and “does changing only the password clear sessions,” you can answer this article’s question. An untouched official vault does not mean the saved list on this machine is still only yours. LastPass held the cloud side it could hold. The batch you clicked Save on in the browser, and the Discord, Steam, and Telegram sessions that are still alive, do not empty because you read a line that says the company was not hacked. The download source and a clean device are a place to check. They are a poor place to assume “I only installed an authenticator, so this is over.”

FAQ

LastPass itself was not breached. Do I still have to change passwords?

It depends on which download you opened. “Official systems and customer vaults were not breached” covers the side installed from lastpass.com and the official stores. If this Windows PC ran an unofficial installer from search, saved browser passwords, sessions, and wallets are still treated as already gone. Trust the download path. Do not let the brand name in a headline stand in for that look.

I already deleted the installer. Can I change passwords on this computer?

That is not a clean bill. The joint note says change them from another device you can confirm is clean. It also says reads can continue after a reboot. Switch devices first, then rotate the accounts this computer’s browser once saved, and revoke the chat sessions.

I only installed the authenticator from the official phone store. Do I rotate saved browser passwords?

For this joint note, the official-store path was not written as the entry. The browser saved list is a separate everyday leftover. If this computer was also read by some other program of unknown origin, that list can still leave. “The company was not hacked” does not prove you never clicked Save in some other download.

Do create and read need an account? If I delete the wrong one, can support recover it?

No sign-up. Create and read are public to a visitor. After ciphertext burns by count or expiry, there is no server-side plaintext backup and no support inbox that can recover it. Generate a new password and a new link. Do not keep refreshing the same URL to see if it comes back, and do not leave the result page on a computer that may already have been read so you can resend it.