Mangwu Security Team Discovers a Malicious GitHub Repository Pretending to Be the qwen 3.8 Model
2026-08-28 20:33:43
According to CoinMeta, Moofaw Security Team disclosed the discovery of a repository named GitHub that impersonated a 3.827B local quantification model named qwen. The nominal size of this model was claimed to exceed 16 GB, but the actual downloaded content was only about 487 KB. This repository contained disguised files, an luajit interpreter, and obfuscated lua scripts. Moofaw emphasized that the official qwen project was not compromised. Once this malicious program ran, it would collect host data, capture screenshots, and send them to the attacker. When the hardcoded server failed, it would also read a backup C2 address from contracts on the Polygon chain, allowing the attacker to rotate infrastructure through on-chain transactions. Subsequent payloads could steal browser login information, cookie, browsing history, emails, winscp, steam credentials, as well as wallet-related files and additional data. Moofaw also found that at least 23 more GitHub repositories and 29 similar compressed packages used the same lua delivery chain.
Bullish 0
Bearish 0
Source:X
This content is for market information only and does not constitute investment advice.