SlowMist Flags Fake Qwen 3.8 27B GitHub Repository Concealing StealC Information

cryptonews.ru發佈於 2026-08-28更新於 2026-08-28

文章摘要

SlowMist has identified a fake GitHub repository impersonating Alibaba's Qwen 3.8 27B AI model, which contains an information-stealing virus. The repository, created in August 2026, offered a download file of only 487 KB, far smaller than a legitimate 27-billion-parameter model (over 16 GB). The malicious ZIP file contained a Lua-based script disguised as a certificate, which deploys the StealC malware. Once executed, StealC harvests system data, takes screenshots, and steals browser credentials, cryptocurrency wallet information, and more, sending it to attacker-controlled servers. The malware also includes a backup system that can read new server addresses from the Polygon blockchain if the primary server is taken down. This incident is part of a broader campaign called FakeGit, active since March 2025, which has created thousands of malicious repositories. Approximately 800 of these specifically target AI tools using a method called AgentBaiting, sometimes tricking AI assistants into recommending them. Separate reports detail hundreds of other fake GitHub repositories spreading malware like BoryptGrab and campaigns like Megalodon that generate thousands of clones rapidly. Attackers copy legitimate projects, create convincing documentation, and even list them on public AI registries to appear trustworthy. The fake repositories exploit the high demand for open-source AI capabilities, putting users who run models locally at significant risk of data theft.

A virus designed to steal information was uploaded to a GitHub repository, masquerading as downloadable weight files for Alibaba's Qwen 3.8 27B model.

The SlowMist security team reported this on August 28th, and anyone running open-source AI models locally could be at risk of data theft.

There is a Fake Qwen AI Model on GitHub

On August 28, the SlowMist security team warned that someone had created a fake page on GitHub that appeared to offer the popular Qwen AI model for download. The page convincingly promised a fully autonomous AI that would ensure user data privacy, but the file size gave away the trap.

The ZIP file size in this fake repository was only 487 KB, less than half a megabyte, while a real 27-billion-parameter AI model takes up over 16 GB of computer space.

The malicious ZIP file, named uncensored_qwen_v2.6.zip, was created on August 20, 2026, and four days later, the attackers edited the README page so that all download links pointed directly to the malicious ZIP file.

The genuine Alibaba Qwen project was not affected by this.

The ZIP archive contained three files: a command file, an executable program, and a script disguised as a certificate. The executable is a renamed version of the LuaJIT interpreter, a tool used by game engines. It is not dangerous by itself, but the script disguised as a certificate file deploys a virus known as StealC.

Once run on a computer, StealC collects the system name, username, machine identifier, and Windows version. It takes a screenshot and then sends all this data to a server controlled by the attackers. The virus can also steal browser login data, cookie files, browsing history, email passwords, and even cryptocurrency wallet information.

The attackers also created a backup system that allows the virus to read a backup server address from a smart contract on the Polygon blockchain in case the main server goes offline. This system allows the attackers to change their server's location without needing to update the virus code on infected computers.

How Often are Trojan Programs Uploaded to GitHub?

SlowMist discovered at least 23 other GitHub repositories and 29 similar ZIP files using the same Lua-based delivery chain. Island.io discovered and reported on a campaign dubbed FakeGit, active since March 2025, which created about 7,600 malicious GitHub repositories and generated over 14 million download events.

Of these 7,600, 800 are specifically designed to mimic AI-related tools, using a method called AgentBaiting. They can even trick AI assistants into recommending them.

In January, Cryptopolitan reported that Alibaba's real Hugging Face models had been downloaded over 700 million times, the highest among all open-source AI systems.

In late June, at least 292 GitHub repositories copying well-known brands were identified. These fake repositories were spreading the BoryptGrab virus, which steals data from 32 different cryptocurrency wallets and 19 web browsers.

Separately, the cybersecurity company InfoStealers described another automated attack called Megalodon, which resulted in the creation of over 5,000 fake repositories in just six hours.

The attackers copy real projects, create convincing README pages, and even use stolen personal data. They also list these fake projects on public AI registries like LobeHub and Glama, making them more trustworthy.

Cryptopolitan wrote about the same tactic when the StopAndProtect operation turned nearly 2,000 hacked WordPress sites into traps for cryptocurrency users.

Island reports that these repositories are created to meet the growing demand for AI capabilities.

相關問答

QWhat was the fake repository on GitHub impersonating, according to the SlowMist team's report?

AThe fake repository on GitHub was impersonating downloadable weight data for Alibaba's Qwen 3.8 27B AI model.

QWhat was the key giveaway that the GitHub repository was fake, as mentioned in the article?

AThe key giveaway was the size of the ZIP file. It was only 487 KB, while a real 27-billion-parameter AI model would require over 16 GB of storage space.

QWhat specific malware was hidden inside the malicious ZIP file, and what information does it steal?

AThe malware hidden inside the ZIP file was StealC. It steals system name, username, machine ID, Windows version, takes screenshots, and can steal browser login data, cookies, browsing history, email passwords, and cryptocurrency wallet information.

QWhat method do the attackers use to maintain control if their primary server is taken down?

AThe attackers use a backup system that allows the virus to read the address of a backup server from a smart contract on the Polygon blockchain if the primary server is disconnected.

QHow widespread is the issue of fake repositories on GitHub, based on the figures provided in the article?

AThe issue is widespread. Island.io reported a campaign called FakeGit that has created about 7,600 malicious GitHub repositories and generated over 14 million download events since March 2025. Of these, 800 specifically impersonate AI-related tools.

你可能也喜歡

从兜售数据库到出售活跃会话访问权限:俄罗斯黑市如何变迁

俄罗斯暗网市场发生显著转变:犯罪分子的重点从出售大规模企业数据库,转向贩卖对用户账户的短期实时访问权限。这类通过恶意软件直接从受感染设备窃取的实时信息,其价值在过去一年上涨近13%。如今黑市上热销的不再是过时的数据档案(售价仅10-15美元),而是包含活跃会话令牌、有效密码、VPN及云存储凭证、企业网络管理权限等能实现即时入侵的工具包。订阅提供每日新鲜数据流的私密频道,每月费用高达250-300美元,市场为时效性而非数据量付费。 官方统计显示,自2024年以来,大规模数据泄露事件数量因严厉制裁而减少,监管机构也对造成泄露的企业处以罚款。然而,这种监管模式对新威胁模型失效。恶意软件是在数据离开企业防护边界、到达个人设备后才实施窃取,企业数据库形式上未受损,从而规避了监管机制。 这种在终端设备上截取数据的方式可绕过多因素认证等企业多层防护。2026年上半年,约60%的Web攻击旨在获取入侵企业内部系统的密钥。一个受感染的员工设备就足以使受保护网络门户大开。 当前趋势与国际网络犯罪演变路径一致,类似Genesis Market的模式此前已被取缔。但这并未消除感染源,只是转移了销赃渠道。这种模式还催生结构性风险:对“新鲜”数据的持续需求,激励僵尸网络运营商长期维持受感染设备的活跃状态,将其变为持续收入来源。 核心矛盾在于,攻击发生在企业防护边界与个人设备之间的监管空白地带。随着远程操作普及,能同时访问多个服务的短期令牌价值将持续攀升,而现有保护法规对此领域尚难有效覆盖。

cryptonews.ru2 小時前

从兜售数据库到出售活跃会话访问权限:俄罗斯黑市如何变迁

cryptonews.ru2 小時前

交易

現貨
活动图片