< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

AI security: Malicious Qwen model found on GitHub and Z.ai releases GLM-5.3

Security analysts have identified a malicious GitHub repository disguised as downloadable weights for Alibaba’s Qwen 3.8 27B AI model. The SlowMist security team reported that the fake repository, which promised a private offline AI, contained a ZIP file of only 487 KB—significantly smaller than the actual 16 GB required for a model of that scale.

The malicious file contains the StealC virus, which can collect system information, take screenshots, and steal browser credentials, cookies, email passwords, and cryptocurrency wallet data. The attackers utilized a fallback system that reads server addresses from a smart contract on the Polygon blockchain to maintain connectivity.

In a separate development, Z.ai has released the weights for its GLM-5.3 model under an MIT license, making it available to individuals. However, the company has implemented a restriction for hyperscale companies—those clearing over $10 billion in annual revenue—requiring them to pass a Z.ai security review before commercial use. The model is noted for its high performance in vulnerability discovery benchmarks, having reportedly identified thousands of vulnerabilities in open-source projects.

Entities

Alibaba · GitHub · Polygon · SlowMist · Z.ai