New ChocoPoC malware targets researchers via trojanized PoC exploits
Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering ChocoPoC, a Python-based remote access trojan (RAT) capable of executing commands and stealing sensitive data. The campaign is believed to target cybersecurity researchers.
- Disclosed
- Last updated
- Blast radius
- Cybersecurity researchers and security professionals who downloaded trojanized PoC exploits from GitHub
- Ecosystems
- Attack vectors
- Affected entities
- ChocoPoC malwarePython-based remote access trojan (RAT) delivered via trojanized PoC exploits on GitHub
A campaign has been identified distributing trojanized proof-of-concept (PoC) exploits on GitHub that deliver ChocoPoC, a Python-based remote access trojan (RAT). The malware is capable of executing arbitrary commands and exfiltrating sensitive data from infected systems.
The attack appears to be specifically targeting cybersecurity researchers who download and execute these PoC exploits, likely as part of their security research or vulnerability analysis work. The use of GitHub as a distribution vector and the targeting of security professionals suggests a sophisticated social engineering approach.
The incident represents a supply chain attack vector where legitimate-appearing security research materials are weaponized to compromise researchers and security professionals who would normally be expected to handle such code with caution.
Indicators of compromise
- Packages
- ChocoPoC
Remediation
- Audit GitHub repositories for trojanized PoC exploits and remove malicious versions
- Review execution logs for any PoC exploits downloaded from GitHub, particularly those related to recent vulnerabilities
- Scan systems for ChocoPoC indicators of compromise (IoCs) and remote access trojan signatures
- Implement code review and sandboxing practices before executing any PoC exploits
- Monitor for suspicious command execution and data exfiltration from researcher systems
- Update security tools to detect ChocoPoC malware variants
Sources
- New ChocoPoC malware targets researchers via trojanized PoC exploits · BleepingComputer
Cite this entry
"New ChocoPoC malware targets researchers via trojanized PoC exploits." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 1, 2026; last updated July 1, 2026. https://supplychainattack.org/incident/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits-1wwsq2
Suggest a correction
Found an error or have a newer source? Corrections to factual errors take priority over new entries.
Related incidents
- containedcritical
Malicious code in @antv/li-editor (npm)
A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/li-editor, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-mock-data (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-mock-data, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/interaction (npm)
The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/interaction, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit - containedcritical
Malicious code in @antv/gi-public-data (npm)
The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-public-data was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.
Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit