星球日报
星球日报|Aug 28, 2026 12:42
[SlowMist: Malicious GitHub Repository Disguised as Qwen Model Discovered] Odaily Planet Daily reports that the SlowMist security team has disclosed the discovery of a GitHub repository impersonating the Qwen 3.8 27B local quantization model. The repository claims the model size should exceed 16 GB, but the actual download content is only about 487 KB, containing disguised files, a LuaJIT interpreter, and obfuscated Lua scripts. SlowMist emphasizes that the official Qwen project has not been compromised. According to SlowMist's analysis, once the malicious program is executed, it collects host data, captures screenshots, and sends them to the attacker's C2 server. If the hardcoded server becomes unavailable, it retrieves backup C2 addresses from a contract on the Polygon blockchain, enabling the attacker to rotate infrastructure through on-chain transactions. Subsequent payloads can steal browser login credentials, cookies, browsing history, email accounts, WinSCP, Steam credentials, as well as wallet-related files and extension data. SlowMist also discovered at least 23 GitHub repositories and 29 similar compressed files using the same Lua delivery chain.
+6
Mentioned
Share To

Timeline

HotFlash

APP

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads