Mangwu Security Team Discovers a Malicious GitHub Repository Pretending to Be the qwen 3.8 Model
2026-08-28 20:33:43
According to CoinMeta, Moofaw Security Team disclosed the discovery of a repository named GitHub that impersonated a 3.827B local quantification model named qwen. The nominal size of this model was claimed to exceed 16 GB, but the actual downloaded content was only about 487 KB. This repository contained disguised files, an luajit interpreter, and obfuscated lua scripts. Moofaw emphasized that the official qwen project was not compromised. Once this malicious program ran, it would collect host data, capture screenshots, and send them to the attacker. When the hardcoded server failed, it would also read a backup C2 address from contracts on the Polygon chain, allowing the attacker to rotate infrastructure through on-chain transactions. Subsequent payloads could steal browser login information, cookie, browsing history, emails, winscp, steam credentials, as well as wallet-related files and additional data. Moofaw also found that at least 23 more GitHub repositories and 29 similar compressed packages used the same lua delivery chain.
Source:X
This content is for market information only and does not constitute investment advice.
Follow CoinMeta official accounts to stay updated

Hot Articles
Refresh

'No longer a distant place': F2Pool Co-founder Chun Wang joins SpaceX's 2-year mission to Mars
05-22 18:25

Polymarket Targets Japan Approval Despite Gambling Laws
05-22 18:00

ZachXBT flags suspected exploit involving Polymarket's UMA adapter contract on Polygon
05-22 17:57

ZachXBT flags $520K Polymarket exploit on Polygon, team says funds are safe
05-22 17:24

Verus bridge exploiter returns 4,052 ETH, retains $2.8 million bounty: onchain analyst
05-22 17:24



