Threat Intelligence | The StealC Info-Stealing Chain Behind the Qwen Impersonation Repository
A GitHub repository impersonating the Qwen AI model distributed a malicious ZIP file containing an information-stealing Trojan named StealC. The repository redirected users to download the malicious file, which contained a Lua interpreter and obfuscated script designed to collect sensitive data including browser credentials, cryptocurrency wallets, and system information. The malware uses a multi-stage delivery chain, with C2 communication falling back to an Ethereum RPC call on the Polygon chain.
- Chains
- Polygon
- Confidence
- High
- First seen
- 28 Aug 2026, 11:01 UTC