🚨 THREAT ALERT: Fake $QWEN repo dropping StealC malware

SlowMist caught a GitHub repo impersonating Qwen 3.8 27B quantized weights. Red flag: real Q4_K_M 27B = 16+ GB. This? 487 KB. No GGUF. Just 3 files—cmd, LuaJIT, obfuscated Lua.

Official Qwen is clean. Malicious ZIP hidden in assets/. Post-deobfuscation: script grabs host data, screenshots, POSTs to C2. If C2 fails, it reads fallback from a Polygon contract via eth_call. One on-chain tx = instant infra rotation.

Inner payload = StealC. Targets:
🔹 Browser logins, cookies, history (Chrome App-Bound bypass)
🔹 Email, WinSCP, Steam creds
🔹 Wallet files + extension data

MistEye tracked 29 similar ZIPs across 23 repos. Same Lua stack. Between snapshots: repos, filenames, PE, AES key all rotated.

27B model in 487 KB = not a model. Check asset size. Unpack before running. Stay safe anons.