SlowMist|Aug 28, 2026 11:10
🚨 Threat Intelligence | The StealC Info-Stealing Chain Behind the Qwen Impersonation Repository
SlowMist Security Team identified a #GitHub repository impersonating local quantized weights for Qwen 3.8 27B. A real Q4_K_M 27B package should exceed 16 GB. The asset delivered was only 487 KB — no GGUF weights, just three files: Application.cmd, a renamed LuaJIT interpreter, and an obfuscated Lua script disguised as cert.txt.
The official #Qwen project was not compromised. The repo kept the look of a normal offline model project, while the malicious ZIP sat in assets/. After deobfuscation, the script collects host data, takes a screenshot, and POSTs them to C2. When the hardcoded server fails, it reads a fallback C2 from a Polygon contract via eth_call, so operators can rotate infrastructure with a single on-chain transaction.
Preserved C2 responses then delivered an inner payload we attribute to #StealC, targeting:
🔹 Browser logins, cookies, and history — including a Chrome App-Bound Encryption bypass
🔹 Email, WinSCP, and Steam credentials
🔹 Wallet-related files and extension data, dispatched by server-side tasks
MistEye reconstructed the multi-stage chain and compared 29 similar ZIPs across 23 repositories using the same Lua delivery stack. Between two collection dates, repositories, filenames, the outer PE, and the AES key had already rotated.
A 27B model that downloads in 487 KB is not a model. Inspect asset size and unpack downloaded packages before running them.
Read the full analysis 👇
https://slowmist.medium.com/threat-intelligence-the-stealc-info-stealing-chain-behind-the-qwen-impersonation-repository-8fead425e94e(SlowMist)
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink