Màn Vũ discovers a malicious GitHub repository disguised as a Qwen model, stealing user data
2026-08-28 20:42:46
According to CoinMeta, the SlowMist security team discovered a repository named GitHub that impersonated the Qwen 3.8 27b local quantification model. This model was supposed to be over 16 GB in size, but the actual downloaded content was only 487 KB. It contained disguised files, a luajit interpreter, and obfuscated lua scripts. Once the malicious program ran, it collected host data, took screenshots, and sent them to the attacker's C2. If the server failed, it would read a backup address from a contract on the Polygon chain. Subsequently, the payload stole browser login information, cookie, browsing history, email addresses, winscp, steam credentials, and wallet data. SlowMist found that at least 23 GitHub repositories and 29 compressed packages used the same lua delivery chain.
Source:Internet
This content is for market information only and does not constitute investment advice.
Follow CoinMeta official accounts to stay updated

Hot Articles
Refresh

'No longer a distant place': F2Pool Co-founder Chun Wang joins SpaceX's 2-year mission to Mars
05-22 18:25

Polymarket Targets Japan Approval Despite Gambling Laws
05-22 18:00

ZachXBT flags suspected exploit involving Polymarket's UMA adapter contract on Polygon
05-22 17:57

ZachXBT flags $520K Polymarket exploit on Polygon, team says funds are safe
05-22 17:24

Verus bridge exploiter returns 4,052 ETH, retains $2.8 million bounty: onchain analyst
05-22 17:24



