SlowMist Flags Fake Qwen 3.8 27B GitHub Repository Hiding StealC Info-Stealer

DN19 Newsroom
28 Aug 2026 16:24
Coins 0 8
3 minutes reading

A malware campaign disguised as downloadable model weights for Alibaba’s Qwen 3.8 27B AI model has targeted GitHub users who run open-source artificial intelligence models locally. SlowMist’s security team reported the threat on August 28, warning that the malicious files can steal credentials and other sensitive data.

Fake Qwen AI model hosted on GitHub

The fraudulent GitHub repository was designed to look like an official download page for Qwen, promising users a fully offline AI model that would keep their data private. However, the repository’s file size revealed the deception.

The ZIP archive was just 487 KB, or less than half a megabyte. A genuine AI model with 27 billion parameters typically requires more than 16 GB of storage.

Named uncensored_qwen_v2.6.zip, the malicious archive was created on August 20, 2026. Four days later, the attackers modified the repository’s README file so that every download link led directly to the harmful ZIP file.

Alibaba’s legitimate Qwen project was not affected by the incident.

StealC malware targets passwords and crypto wallets

The archive contained three files: a command file, an executable program and a script disguised as a certificate. The executable was a renamed version of a LuaJIT interpreter, a tool commonly used by game engines. While the interpreter itself is not inherently dangerous, the fake certificate script uses it to deliver StealC malware.

Once active, StealC collects the infected computer’s system name, username, machine ID and Windows version. It also captures a screenshot and sends the stolen information to an attacker-controlled server.

The malware can additionally target browser login credentials, cookies, browsing history, email passwords and cryptocurrency wallet data.

The attackers added a fallback mechanism that retrieves a backup server address from a smart contract on the Polygon blockchain. If the primary server is taken offline, the attackers can change the malware’s server location without updating the code on infected computers.

Growing number of malicious AI repositories

SlowMist identified at least 23 other GitHub repositories and 29 similar ZIP files that used the same Lua-based delivery chain.

Island.io separately discovered and reported a campaign called FakeGit, which has been active since March 2025. The campaign has reportedly created around 7,600 malicious GitHub repositories and generated more than 14 million download events.

About 800 of those repositories specifically impersonate AI-related tools. They use a technique called AgentBaiting, which can even persuade AI assistants to recommend the malicious projects.

Cryptopolitan reported in January that Alibaba’s genuine models had surpassed 700 million downloads on Hugging Face, more than any other open-source AI system.

In late June, at least 292 GitHub repositories copying well-known brands were flagged. Those repositories distributed BoryptGrab, a malware strain capable of stealing data from 32 cryptocurrency wallets and 19 web browsers.

Separately, security firm InfoStealers described another automated campaign called Megalodon, which created more than 5,000 fake repositories in only six hours.

How attackers make fake GitHub projects look legitimate

Cybercriminals are increasingly copying legitimate projects, creating convincing README pages and using stolen developer identities to make malicious repositories appear authentic. They also list the fake projects in public AI directories such as LobeHub and Glama, increasing their visibility and credibility.

Cryptopolitan previously reported a similar tactic in which the StopAndProtect operation turned nearly 2,000 compromised WordPress websites into traps for cryptocurrency users.

Island.io said the malicious repositories are designed to exploit the growing demand for AI capabilities.

No Comments

Leave a Reply

Your email address will not be published. Required fields are marked *