Security researchers report that the ChocoPoc (ChocoPoC) malware is being delivered through trojanized proof-of-concept (PoC) exploit repositories hosted on GitHub. The campaign uses weaponized-looking Python PoC code that claims to exploit recently discussed or specific vulnerabilities (CVE-related), but executing the code instead installs a Python-based remote access trojan (RAT). Once run, the RAT can execute commands on the compromised system and steal sensitive data, including saved browser credentials and cookies, as well as other files. Multiple sources describe the activity as targeting vulnerability researchers, such as people who test, reproduce, or hunt bugs, by placing the malicious payload within repositories that appear relevant to active research topics. The reports indicate that the PoC repositories are used as delivery mechanisms to reach the intended audience, with the malware initiating follow-on access after data theft. Overall, the disclosures focus on how trusted-looking exploit PoCs on a public code hosting platform can be used to compromise machines when users run the included scripts.
ChocoPoC Python RAT is distributed through trojanized GitHub proof-of-concept exploit repos
Security researchers report that the ChocoPoc (ChocoPoC) malware is being delivered through trojanized proof-of-concept (PoC) exploit repositories hosted on GitHub. The campaign uses weaponized-lookin...
- ChocoPoC is a Python-based remote access trojan (RAT).
- The RAT is distributed via trojanized proof-of-concept (PoC) exploit repositories hosted on GitHub.
- The PoC repositories present code as if it exploits vulnerabilities or newly discussed CVEs.
- When executed, ChocoPoC can run commands and steal sensitive information, including saved passwords and browser cookies.
- The activity is described as targeting cybersecurity vulnerability researchers.
Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs. Run one, and it quietly lifts your saved passwords, browser cookies, and files, then hands the attacker a shell on your machine. YesWeHack and
1 month agoMultiple weaponized proof-of-concept (PoC) exploits on GitHub delivered a Python-based remote access trojan (RAT) called ChocoPoC that can execute commands and steal sensitive data. [...]
1 month agoMultiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers. [...]
1 month ago
PSG chief refuses to rule out Bradley Barcola exit amid Liverpool and Arsenal interest
PSG president Nasser Al-Khelaifi says he cannot give an update on Bradley Barcola’s future, but does not rule out a move...
Flash floods on Nepal-Tibet border kill people and leave hundreds missing
A flash flood and related mudslide hit Nepal’s border district of Rasuwa, washing away villages and damaging roads, brid...
Pakistan women’s captain Fatima Sana says team trained vs men ahead of Asia Cup
Pakistan women’s cricket captain Fatima Sana says her team completes preparation for the Women’s Asia Cup by playing ful...