SlowMist flags fake Qwen model GitHub repo tied to Polygon-based C2 fallback

SlowMist flags fake Qwen model GitHub repo tied to Polygon-based C2 fallback

N
News Editor
2026-08-28 12:42:53
SlowMist has disclosed a malicious GitHub repository posing as a local quantized version of the “Qwen 3.8 27B” model. The security team said the repo claimed the model file should be larger than 16GB, but the actual download was only about 487KB and contained disguised files, a LuaJIT interpreter, and obfuscated Lua scripts. SlowMist added that the official Qwen project itself was not compromised. According to SlowMist’s analysis, the malware collects host information, captures screenshots, and sends the data to an attacker-controlled command-and-control server after execution. If the hardcoded server becomes unavailable, the program can read a backup C2 address from a smart contract on Polygon, allowing the operator to rotate infrastructure through on-chain transactions. SlowMist also said follow-on payloads can steal browser logins, cookies, browsing history, email data, WinSCP and Steam credentials, as well as crypto wallet-related files and extension data. The team found that at least 23 GitHub repositories and 29 similar compressed packages used the same Lua-based delivery chain.

ChainCatcher reported that blockchain security firm SlowMist has disclosed a malicious GitHub repository masquerading as a local quantized version of the “Qwen 3.8 27B” model.

The repository claimed the model file should be larger than 16GB, but the actual download was only about 487KB. SlowMist said the package contained disguised files, a LuaJIT interpreter, and obfuscated Lua scripts. The team added that the official Qwen project was not compromised.

SlowMist’s analysis found that, once executed, the malware collects host information, captures screenshots, and sends the data to an attacker-controlled command-and-control server. If the hardcoded server is no longer available, the malware can retrieve a backup C2 address from a contract on the Polygon blockchain, letting the attacker rotate infrastructure through on-chain transactions.

SlowMist said later-stage payloads can steal browser login data, cookies, browsing history, email data, WinSCP credentials, Steam credentials, and crypto wallet-related files and extension data. The firm also found that at least 23 GitHub repositories and 29 similar compressed packages used the same Lua-based delivery chain.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.