ChocoPoc malware delivered via trojanized exploits on GitHub
Multiple weaponized proof-of-concept exploits on GitHub delivered ChocoPoc, a Python-based remote access trojan capable of executing commands and stealing sensitive data. The malware was distributed through trojanized exploit repositories on the platform.
- Disclosed
- Last updated
- Blast radius
- Unknown; depends on GitHub repository reach and download counts
- Ecosystems
- Attack vectors
- Affected entities
- ChocoPoc malwarePython-based remote access trojan delivered via trojanized PoC exploits on GitHub
ChocoPoc is a Python-based remote access trojan (RAT) that was discovered being delivered via trojanized proof-of-concept (PoC) exploits hosted on GitHub. The malware was embedded in what appeared to be legitimate exploit code, likely targeting developers and security researchers who download PoC code from the platform.\n\nThe trojanized exploits served as the delivery mechanism, allowing the attacker to distribute the RAT to users who cloned or downloaded the repositories. Once executed, ChocoPoc can execute arbitrary commands on the infected system and exfiltrate sensitive data.\n\nThis attack demonstrates a supply chain risk targeting the developer community through GitHub repositories, where PoC code is commonly shared and reused. The use of seemingly legitimate exploit code as a delivery vector increases the likelihood of successful infection among technical users.
Indicators of compromise
- Packages
- ChocoPoc
Remediation
- Audit GitHub repositories for trojanized exploit code; verify integrity of downloaded PoC exploits before execution
- Review system logs for ChocoPoc indicators of compromise (IoCs) and command execution patterns
- Implement code review practices for third-party PoC code before integration or execution
- Monitor for suspicious outbound connections and command execution from Python processes
- Use endpoint detection and response (EDR) tools to identify ChocoPoc RAT activity
Sources
- ChocoPoc malware delivered via trojanized exploits on GitHub · BleepingComputer
Cite this entry
"ChocoPoc malware delivered via trojanized exploits on GitHub." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 1, 2026; last updated July 1, 2026. https://supplychainattack.org/incident/chocopoc-malware-delivered-via-trojanized-exploits-on-github-16ubmk
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @antv/li-editor (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/li-editor, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/g-webgl-compute (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/g-webgl-compute, as part of the "Mini Shai-Hulud" supply chain attack campaign. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/s2-react-components (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/s2-react-components, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/x6-components (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 packages, including @antv/x6-components, in a 22-minute automated burst. Each version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludTeamPCPnpmOtherAccount takeoverCompromised packageMalicious commit