Slow Fog: Discovered counterfeit Qwen model GitHub repository, a malware distribution trap
The Slow Fog security team recently disclosed the discovery of a malicious GitHub repository impersonating the "Qwen 3.8 27B local quantitative model." The repository claims that the model file should exceed 16GB, while the actual downloaded content is only about 487KB, containing disguised files, a LuaJIT interpreter, and obfuscated Lua scripts. Slow Fog emphasizes that the official Qwen project has not been compromised.
Slow Fog's analysis indicates that after the malicious program runs, it will collect host information, capture the screen, and send it to the attacker's C2 server; when the hard-coded server fails, it will also read backup C2 addresses from contracts on the Polygon chain, allowing the attacker to rotate infrastructure through on-chain transactions.
Subsequent payloads can steal browser login information, cookies, history, email, WinSCP, Steam credentials, as well as files and extension data related to cryptocurrency wallets. Slow Fog also found that at least 23 GitHub repositories and 29 similar compressed packages used the same Lua delivery chain.






