SlowMist says fake Qwen 27B GitHub repos were used to spread StealC malware

SlowMist says fake Qwen 27B GitHub repos were used to spread StealC malware

N
News Editor
2026-08-28 12:41:42
SlowMist has disclosed a malware campaign that used GitHub repositories disguised as local quantized Qwen 27B model downloads to deliver StealC infostealer payloads. According to the security firm, one of the fake model files was only 487KB, far smaller than a normal Q4_K_M 27B model weight file, which should be more than 16GB. Instead of model weights, the archive contained a batch file, a renamed LuaJIT interpreter, and an obfuscated Lua script disguised as cert.txt. SlowMist said the malware could collect host information, capture screenshots, and upload data to a command-and-control server. If the preset C2 server became unavailable, the program could query a backup C2 address from a Polygon smart contract using eth_call, allowing the attackers to rotate malicious infrastructure through on-chain transactions. The follow-on payload was attributed to StealC, which can steal browser credentials, cookies, browsing history, email, WinSCP and Steam credentials, as well as crypto wallet files and browser extension data. SlowMist said it found 29 similar malicious archives across 23 GitHub repositories.

Odaily reported that blockchain security firm SlowMist has identified a GitHub repository posing as a local quantized Qwen 27B model and using it to distribute StealC infostealer malware.

According to SlowMist, the supposed model file offered by the attacker was only 487KB. A normal Q4_K_M 27B model weight file should be larger than 16GB. The archive did not contain model weights. Instead, it included a batch file, a renamed LuaJIT interpreter, and an obfuscated Lua script disguised as cert.txt.

SlowMist said its analysis showed the malware could collect host information, capture screenshots, and upload the data to a command-and-control, or C2, server.

The security team also said that if the preset C2 server became unavailable, the malware could use eth_call on a Polygon contract to read a backup C2 address. That setup allowed the attacker to rotate malicious infrastructure through on-chain transactions.

SlowMist attributed the follow-on payload to StealC. It said the malware could steal browser login credentials, cookies, and browsing history, while also bypassing Chrome App-Bound Encryption. It could also obtain email, WinSCP, and Steam credentials, along with crypto wallet-related files and browser extension data.

SlowMist said it found 29 similar malicious archives across 23 GitHub repositories. The firm warned users to be cautious of unusually small AI model files and advised them to check file sizes and inspect archive contents before running them.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1500

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.