ShellCodeX
Tools • Events • News • Insights
SEO Checker
ShellCodeX Intelligence Brief
CRITICAL Cybersecurity

ChocoPoC RAT hides as fake PoC exploit code in GitHub repositories

Source headline: New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 1 month ago

Intelligence Summary

A Python-based RAT dubbed ChocoPoC is being distributed through fake GitHub proof-of-concept exploit repositories. The repos claim to target recently disclosed CVEs but instead deliver a trojan payload. Once run, the malware steals saved passwords, browser cookies, and other files. It then connects back to the attacker and provides a shell for further control. Vulnerability researchers and developers who execute PoC code from unverified sources should treat these repos as high risk and verify provenance before running anything.

Recommended Action

Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.

Topics

#github #rat #python #chocopoc #password-stealing #trojan
Original reporting The Hacker News New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Open original source