BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

SlowMist: Malicious GitHub Repository Disguised as Qwen Model Discovered

2026-08-28 12:41

Odaily News – SlowMist security team has disclosed the discovery of a GitHub repository impersonating the Qwen 3.8 27B local quantized model. The repository claims the model size exceeds 16 GB, but the actual downloaded content is only about 487 KB, containing disguised files, a LuaJIT interpreter, and obfuscated Lua scripts. SlowMist emphasized that the official Qwen project has not been compromised. According to SlowMist's analysis, once executed, the malicious program collects host data, captures screenshots, and sends them to the attacker's C2 server. When the hardcoded server becomes inactive, it reads a backup C2 address from a contract on the Polygon chain, allowing attackers to rotate infrastructure through on-chain transactions. Subsequent payloads can steal browser login credentials, cookies, browsing history, email accounts, WinSCP and Steam credentials, as well as wallet-related files and extension data. SlowMist also discovered at least 23 GitHub repositories and 29 similar archive files using the same Lua delivery chain.