Skip to content
supplychainattack.orgSupply chain attack incident catalog
activehigh

ChocoPoc malware delivered via trojanized exploits on GitHub

Multiple weaponized proof-of-concept exploits on GitHub delivered ChocoPoc, a Python-based remote access trojan capable of executing commands and stealing sensitive data. The malware was distributed through trojanized exploit repositories on the platform.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Unknown; depends on GitHub repository reach and download counts
Ecosystems
Attack vectors
Affected entities
  • ChocoPoc malwarePython-based remote access trojan delivered via trojanized PoC exploits on GitHub

ChocoPoc is a Python-based remote access trojan (RAT) that was discovered being delivered via trojanized proof-of-concept (PoC) exploits hosted on GitHub. The malware was embedded in what appeared to be legitimate exploit code, likely targeting developers and security researchers who download PoC code from the platform.\n\nThe trojanized exploits served as the delivery mechanism, allowing the attacker to distribute the RAT to users who cloned or downloaded the repositories. Once executed, ChocoPoc can execute arbitrary commands on the infected system and exfiltrate sensitive data.\n\nThis attack demonstrates a supply chain risk targeting the developer community through GitHub repositories, where PoC code is commonly shared and reused. The use of seemingly legitimate exploit code as a delivery vector increases the likelihood of successful infection among technical users.

Indicators of compromise

Packages
  • ChocoPoc

Remediation

  • Audit GitHub repositories for trojanized exploit code; verify integrity of downloaded PoC exploits before execution
  • Review system logs for ChocoPoc indicators of compromise (IoCs) and command execution patterns
  • Implement code review practices for third-party PoC code before integration or execution
  • Monitor for suspicious outbound connections and command execution from Python processes
  • Use endpoint detection and response (EDR) tools to identify ChocoPoc RAT activity

Sources

  1. ChocoPoc malware delivered via trojanized exploits on GitHub · BleepingComputer

Cite this entry

"ChocoPoc malware delivered via trojanized exploits on GitHub." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 1, 2026; last updated July 1, 2026. https://supplychainattack.org/incident/chocopoc-malware-delivered-via-trojanized-exploits-on-github-16ubmk

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @antv/li-editor (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/li-editor, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  2. containedcritical

    Malicious code in @antv/g-webgl-compute (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in @antv/s2-react-components (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/s2-react-components, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antv/x6-components (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-components, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit