SlowMist discovers malicious GitHub repositories disguised as Qwen models, stealing user data

--

The SlowMist security team discovered a GitHub repository impersonating the Qwen 3.8 27B local quantization model. The model's nominal size should exceed 16 GB, but the actual downloaded content is only 487 KB, including disguised files, LuaJIT interpreter, and obfuscated Lua scripts. After the malicious program runs, it collects host data, intercepts the screen, and sends it to attacker C2. When the server fails, it reads the backup address from the Polygon on chain contract. Subsequent payloads steal browser login information Cookie、 History, email, WinSCP, Steam credentials, and wallet data. SlowMist discovered that at least 23 GitHub repositories and 29 compressed files are using the same Lua delivery chain.

Loading...