Slow Mist Discovers Fake Qwen Model GitHub Repository

By: x.com|2026/08/28 12:42:53

The Slow Mist security team recently discovered a malicious GitHub repository impersonating the "Qwen 3.8 27B Local Quantitative Model." The repository claims that the model files exceed 16GB, but the actual downloaded content is only about 487KB, containing disguised files, a LuaJIT interpreter, and obfuscated Lua scripts. Slow Mist emphasizes that the official Qwen project has not been compromised. Once executed, the malicious program collects host information, takes screenshots, and sends them to the attacker's C2 server; when the hardcoded server fails, it will read a backup C2 address from contracts on the Polygon chain. Subsequent payloads can steal browser login information, cookies, history, emails, WinSCP, Steam credentials, as well as files and extension data related to cryptocurrency wallets. Slow Mist also found at least 23 GitHub repositories and 29 similar compressed packages using the same Lua delivery chain.

-- Price

--
--
--

This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com