Skip to content
supplychainattack.orgSupply chain attack incident catalog
activehigh

New ChocoPoC malware targets researchers via trojanized PoC exploits

Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering ChocoPoC, a Python-based remote access trojan (RAT) capable of executing commands and stealing sensitive data. The campaign is believed to target cybersecurity researchers.

ShareXLinkedInHacker News
Disclosed
Last updated
Blast radius
Cybersecurity researchers and security professionals who downloaded trojanized PoC exploits from GitHub
Ecosystems
Attack vectors
Affected entities
  • ChocoPoC malwarePython-based remote access trojan (RAT) delivered via trojanized PoC exploits on GitHub

A campaign has been identified distributing trojanized proof-of-concept (PoC) exploits on GitHub that deliver ChocoPoC, a Python-based remote access trojan (RAT). The malware is capable of executing arbitrary commands and exfiltrating sensitive data from infected systems.

The attack appears to be specifically targeting cybersecurity researchers who download and execute these PoC exploits, likely as part of their security research or vulnerability analysis work. The use of GitHub as a distribution vector and the targeting of security professionals suggests a sophisticated social engineering approach.

The incident represents a supply chain attack vector where legitimate-appearing security research materials are weaponized to compromise researchers and security professionals who would normally be expected to handle such code with caution.

Indicators of compromise

Packages
  • ChocoPoC

Remediation

  • Audit GitHub repositories for trojanized PoC exploits and remove malicious versions
  • Review execution logs for any PoC exploits downloaded from GitHub, particularly those related to recent vulnerabilities
  • Scan systems for ChocoPoC indicators of compromise (IoCs) and remote access trojan signatures
  • Implement code review and sandboxing practices before executing any PoC exploits
  • Monitor for suspicious command execution and data exfiltration from researcher systems
  • Update security tools to detect ChocoPoC malware variants

Sources

  1. New ChocoPoC malware targets researchers via trojanized PoC exploits · BleepingComputer

Cite this entry

"New ChocoPoC malware targets researchers via trojanized PoC exploits." supplychainattack.org, Supply Chain Attack Incident Catalog. Disclosed July 1, 2026; last updated July 1, 2026. https://supplychainattack.org/incident/new-chocopoc-malware-targets-researchers-via-trojanized-poc-exploits-1wwsq2

Suggest a correction

Found an error or have a newer source? Corrections to factual errors take priority over new entries.

  1. containedcritical

    Malicious code in @antv/li-editor (npm)

    A threat actor compromised the npm account `atool` and published 631 malicious versions across 314 npm packages, including @antv/li-editor, in an automated 22-minute burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  2. containedcritical

    Malicious code in @antv/gi-mock-data (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/gi-mock-data, in a 22-minute automated burst. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  3. containedcritical

    Malicious code in @antv/interaction (npm)

    The npm account `atool` was compromised and used to publish 631 malicious versions across 314 npm packages, including @antv/interaction, in an automated 22-minute attack. Each malicious version injects a preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence via CI/CD workflow injection and system daemons.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit
  4. containedcritical

    Malicious code in @antv/gi-public-data (npm)

    The npm account 'atool' was compromised and used to publish 631 malicious versions across 314 npm packages in a 22-minute automated burst, part of the "Mini Shai-Hulud" supply chain attack campaign. @antv/gi-public-data was among the affected packages, modified to include a malicious preinstall hook executing an obfuscated Bun script that exfiltrates credentials and establishes persistence.

    Mini Shai HuludnpmOtherAccount takeoverCompromised packageMalicious commit