Flash News

The slow fog safety team discovered a malicious GitHub warehouse that impersonated a qwen 3.8 model

Wu stated that the slow fog safety team had disclosed the discovery of a GitHub warehouse, which was a local quantitative model of qwen 3.8 27b, with a nominal model of 16 GB, but only about 487 KB was actually downloaded, containing a disguise document, a Luajit interpreter and a confusing lua script. The slow fog stressed that the qwen official project had not been invaded. The malware program, when run, collects host data, intercepts screens and sends them to the attacker C2 when the hard-coded server fails, and also reads the backup C2 address from the Polygon chain, so that the attacker can rotate infrastructure through the chain. Follow-up loads can steal browser login information, cookies, historical records, mailboxes, winsp, steam vouchers, and wallet-related documents and extension data. The slow fog also found at least 23 GitHub warehouses and 29 similar compressor packages using the same lua delivery chain。

OKX - Unlock Rewards