Invest1 distinct publisher3 min readPublished
SlowMist's August 28 report describes a GitHub page promising offline Qwen 3.8 27B weights and handing over a 487KB stealer instead. The byte count on a download is the cheapest integrity control a team still owns.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
The tell cost nothing to compute. Sixteen gigabytes expressed in kilobytes is 16,777,216, and dividing by the 487 that actually arrived leaves a shortfall of about 34,450 times, which is to say the download was roughly three thousandths of one percent of the thing it claimed to be [2][3]. Any wrapper script can do that subtraction before it unzips anything.
Where the operator did spend was distribution. The payload is commodity StealC, and the executable inside was a renamed LuaJIT interpreter, harmless by itself, doing the work of looking boring to a scanner while a file dressed as a certificate pulled the stealer in [5][1]. The archive sat in place and the README was rewired four days later so that every download link pointed at it [4], and campaigns of this shape also get listed in public AI registries such as LobeHub and Glama, where a listing reads as provenance [19]. (The source dates the ZIP to August 20, 2026 while dating the SlowMist report to August 28, which does not reconcile, and I would want the repository metadata before building a timeline on it [4][1].)
The unit economics explain why takedown is a subscription rather than a remedy. Island.io's FakeGit campaign, running since March 2025, has produced roughly 7,600 malicious repositories against more than 14 million download events, which averages about 1,842 downloads per repository [9][12], and 800 of those, one in ten, wear AI clothing under the AgentBaiting label that also aims at getting assistants to recommend them [10][11]. Megalodon, per InfoStealers, spun up more than 5,000 repositories in six hours, roughly 833 an hour [16][17]. Against a supply curve like that, verifying locally matters more than reporting any single repository.
Demand is the other half of it. Alibaba's genuine models passed 700 million downloads on Hugging Face [13], which is what makes the costume worth sewing, and the fake page sold exactly what that population wants, a fully offline model that keeps data on the machine [20]. The machine in question generally also holds browser cookies, saved logins and wallet material, all of which StealC enumerates and ships out alongside a screenshot [6].
This is probably wrong within a quarter, but for now byte count is the highest-yield control per line of code available to anyone pulling local weights. The counter-thesis is plain: a size check tests laziness rather than intent, and the day an archive arrives at the advertised 16GB with real quantized weights and a compromised loader the arithmetic goes quiet. The resilience already on display argues that day is coming, since the malware reads a backup server address from a Polygon smart contract so the operators can move infrastructure without touching code on infected machines [7], and the 292 brand-copying repositories flagged in late June pushing BoryptGrab across 32 wallets and 19 browsers suggest a high iteration rate [15].
Most teams still are not checking publisher identity or hashes at all, and that gap is exactly why the crude control earns its place: it catches every attack that left the file size unpadded.
Ranked by verification strength, evidence, and original report placement.
SlowMist reported on August 28 that a GitHub repository impersonating Qwen 3.8 27B weights delivered a 487 KB StealC info-stealer instead of model weights.
The ZIP file on the fake repository was only 487 KB, while a real 27-billion-parameter model takes up more than 16 GB.
The malicious ZIP, named uncensored_qwen_v2.6.zip, was created on August 20, 2026, and four days later the attackers edited the README so all download links pointed to it.
The ZIP contained three files: a command file, an executable that was a renamed LuaJIT interpreter, and a script disguised as a certificate that brings in the StealC malware.
StealC collects system name, username, machine ID and Windows version, takes a screenshot and sends the data to an attacker-controlled server, and can steal browser logins, cookies, history, email passwords and cryptocurrency wallet information.
The malware has a fallback that reads a backup server address from a smart contract on the Polygon blockchain, letting the attackers change server location without updating code on infected computers.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 28, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
Thomson Reuters spent $40M to make a $450K training run worth doing2 distinct publishers
security
Aeternum puts botnet C2 on Polygon, and leaves defenders no domain to seize1 distinct publisher
product
A billion downloads, and nobody will say what a download is1 distinct publisher
build
Thomson Reuters priced the middle path at $40M, and still pays Anthropic4 distinct publishers
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor note, one relay
Every sharp fact here — the 487 KB, the three-file bundle, the renamed LuaJIT binary, the Polygon fallback — traces to SlowMist's August 28 write-up as summarised by Cryptopolitan, with no link to the advisory, no indicators a defender could load, and no response from GitHub or Alibaba. The wider numbers thin out further: Island.io's campaign totals are secondhand, the 292-repository BoryptGrab cluster has no named finder, and the Megalodon figure is credited to a firm the piece identifies only as InfoStealers. What holds regardless of trust is the arithmetic in the headline: no 27B checkpoint compresses to half a megabyte, so the central deception is self-evident from the file listing.
Attacker side counted, victim side blank
Spread is documented on the offense: 23 sibling repositories and 29 archives on the same Lua chain per SlowMist, and roughly 7,600 repositories with 14 million download events under Island.io's FakeGit label, 800 of them dressed as AI tooling. Set against Qwen's reported 700 million legitimate downloads, the target pool is obviously large. What nobody counts is uptake of the trap itself — no installs, no infected hosts, no download tally for this particular archive, and no evidence that the repository or its siblings have come down.
Scale oversold, core finding sober
The incident is described more carefully than the landscape around it. A 34,000-fold shortfall sounds enormous and is simply what it looks like when a stealer wears a model's name — the claim is modest and checkable. The stretch is in the surrounding sweep: four branded campaign names in six paragraphs, an assertion that AgentBaiting can make AI assistants recommend these repositories with not one demonstrated instance, and aggregate totals that arrive already packaged by the firms that sell against them. The framing also flatters the byte-count check as an integrity control when it is only a smell test; checksums and signed releases go unmentioned.
Named-campaign economics
Look at who benefits from each figure. SlowMist audits crypto infrastructure and gains visibility from being first to name a wallet-stealing chain; Island.io sells enterprise browser security and supplies both the FakeGit branding and the AgentBaiting coinage; the Megalodon and BoryptGrab labels arrive the same way. Naming an operation is how security firms turn telemetry into reach, and this story reprints four such names without discount. Cryptopolitan's own hand shows too: it cites its January Qwen download figure and its StopAndProtect coverage, then closes on a newsletter pitch. None of that makes the 487 KB archive less real — the artifact detail is too specific to be promotional — but the campaign totals should be read as marketing arithmetic.
Believable, thinly attested
We would stand behind the shape of this — an impersonation repository serving a stealer, with the file size as the tell — and behind the arithmetic that exposes it. We would not yet stand behind the perimeter: a single relaying outlet, no advisory text, four unverified campaign figures, an archive timestamp and a model designation that nobody in this coverage checked against Alibaba's releases, and silence on whether the repository still exists. One corroborating security report would move this a long way.