Malicious Qwen Model Virus Spreads Through GitHub
A malicious virus was uploaded to a GitHub repository disguised as downloadable weights for Alibaba's Qwen 3.8 27B model.
The fake repository, which was created on August 20, 2026, convincingly promised a fully offline AI that would keep user data private, but the trap was given away by the file size, which was less than half a megabyte.
A real AI model with 27 billion parameters takes up more than 16 GB of space on a computer.
The malicious ZIP file contained three files: a command file, an executable program, and a script that looks like a certificate. The executable is a renamed version of a LuaJIT interpreter, which is a tool used by game engines.
Once it's running on a computer, the virus collects system name, username, machine ID, and Windows version, takes a screenshot, and sends all this data to a server controlled by the attackers.
The virus can also steal browser login details, cookies, browsing history, email passwords, and even cryptocurrency wallet information.