Màn Vũ discovers a malicious GitHub repository disguised as a Qwen model, stealing user data
2026-08-28 20:42:46
According to CoinMeta, the SlowMist security team discovered a repository named GitHub that impersonated the Qwen 3.8 27b local quantification model. This model was supposed to be over 16 GB in size, but the actual downloaded content was only 487 KB. It contained disguised files, a luajit interpreter, and obfuscated lua scripts. Once the malicious program ran, it collected host data, took screenshots, and sent them to the attacker's C2. If the server failed, it would read a backup address from a contract on the Polygon chain. Subsequently, the payload stole browser login information, cookie, browsing history, email addresses, winscp, steam credentials, and wallet data. SlowMist found that at least 23 GitHub repositories and 29 compressed packages used the same lua delivery chain.
Bullish 0
Bearish 0
Source:Internet
This content is for market information only and does not constitute investment advice.