An information-stealing virus was uploaded to a GitHub repository disguised as downloadable weights for Alibaba’s Qwen 3.8 27B model. SlowMist’s security team reported the incident on August 28, and anyone who runs open-source AI models locally could be at risk of credential theft.There’s a fake Qwen AI model on GitHub On August 28, the SlowMist security team warned that someone had created a fake page on GitHub that looked like it offered the popular Qwen AI model for download. The page convincingly promised a fully offline AI that would keep user data private, but the trap was given away by the file size. The ZIP file on this fake repository was only 487 KB, which is less than half a megabyte, meanwhile a real AI model with 27 billion parameters takes up more than 16 GB of space on a computer. The malicious ZIP file, named uncensored_qwen_v2.6.zip, was created on August 20, 2026, and four days later, the attackers edited the README page so that all download links pointed directly to the harmful ZIP file. The real Alibaba Qwen project has not been affected by this at all. Inside the ZIP were three files: a command file, an executable program, and a script that looks like a certificate. The executable is a renamed version of a LuaJIT interpreter, which is a tool used by game engines. It is not dangerous by itself, but the script, which is disguised as a certificate file, brings in the virus, known as StealC.Once it is running on a computer, StealC collects the system name, username, machine ID, and Windows version. It takes a screenshot and then sends all this data to a server controlled by the attackers. The virus can also steal browser login details, cookies, browsing history, email passwords, and even cryptocurrency wallet information. The attackers also set up a fallback system that allows the virus to read a backup server address from a smart contract on the Polygon blockchain in case their main server gets shut down. The system allows the attackers to change their server location without having to update the virus code on infected computers.How often do Trojan models get uploaded on GitHub? SlowMist found at least 23 other GitHub repositories and 29 similar ZIP files using the same Lua-based delivery chain. Island.io discovered and reported a campaign called FakeGit, active since March 2025, that has created around 7,600 malicious GitHub repositories and generated more than 14 million download events. 800 of those 7,600 are specifically designed to impersonate AI-related tools, using a technique called AgentBaiting. They can even trick AI assistants into recommending them.Cryptopolitan reported in January that Alibaba’s actual models had crossed 700 million downloads on Hugging Face, the most of any open-source AI system.In late June, at least 292 GitHub repositories that copied well-known brands were flagged. These fake repositories pushed a virus called BoryptGrab, which steals data from 32 different cryptocurrency wallets and 19 web browsers. Separately, a security firm called InfoStealers described another automated attack named Megalodon that created more than 5,000 fake repositories in just six hours.Attackers now copy real projects, create convincing README pages, and even use stolen developer identities. They also list these fake projects in public AI registries like LobeHub and Glama, making them seem more trustworthy. Cryptopolitan wrote about the same tactic when the StopAndProtect operation turned nearly 2,000 hacked WordPress websites into traps for cryptocurrency users.Island reports that the repositories are built to meet the growing demand for AI capabilities. The smartest crypto minds already read our newsletter. Want in? Join them.