A malicious GitHub repository posing as a "Qwen 27B local quantized model" was found to contain a batch file, a renamed LuaJIT interpreter and an obfuscated Lua script disguised as cert.txt in a package of about 487KB, even though normal Q4_K_M 27B model weights should exceed 16GB. SlowMist said the malware gathers host information, captures screenshots and uploads data to a C2 server. If the preset server becomes unavailable, it uses eth_call on a Polygon contract to retrieve a backup C2 address, allowing infrastructure to be rotated through on-chain transactions. The later payload was attributed to StealC and can target browser logins, cookies, browsing history, Chrome App-Bound Encryption, email, WinSCP and Steam credentials, plus cryptocurrency-wallet files and browser extension data. SlowMist said the official Qwen project was not compromised and identified 23 GitHub repositories containing 29 similar malicious archives.