ChocoPoC is a new Remote Access Trojan (RAT) targeting vulnerability researchers , hidden within fake proof-of-concept (PoC) exploit code repositories on GitHub . ChocoPoC was discovered and publicly disclosed on July 1, 2026, by cybersecurity firms Sekoia and YesWeHack , who warned that the malware and its infrastructure remained active at the time of publication. The campaign exploits researchers’ urgent need to test new vulnerabilities immediately after they are discovered, turning an everyday professional practice into an attack vector.
See also: VS Code Tasks: Stolen npm and Go packages download Python infostealer

The technique used by ChocoPoC is particularly sneaky: the malware is not contained within the exploit file, but rather hidden in the dependencies of the Python project. When the researcher clones the repository and runs pip install to install the required libraries, the frint, which in turn pulls in a second malicious package, skytext. Skytext contains a small compiled file — gradient.so on Linux or gradient.pyd on Windows — that is activated when the PoC is launched. This architecture makes ChocoPoC difficult to detect by static analysis or simple sandbox environments, as the malware remains dormant unless it encounters the EXPLOIT_POC.py or a similar file in the PoC.
ChocoPoC: Full RAT capabilities and C2 mechanism
Once activated, ChocoPoC acts as a full-fledged Remote Access Trojan with extensive data theft capabilities. It extracts saved passwords, cookies, autofill data, and browsing history from Chrome, Brave, Edge , and Firefox. In addition, it collects text files, notes, local databases, shell, network settings, and a list of running processes. The attacker can execute any shell, run arbitrary Python code, and download entire folders from the victim’s system. It is noteworthy that some commands are written in Spanish and the code contains small bugs, suggesting that it was written manually and not with the help of AI.
One of the most interesting technical features of ChocoPoC is the use of the Mapbox API as a hidden Command-and-Control (C2). By leveraging a legitimate mapping service API, the malware evades typical security filters that look for known malicious infrastructure. For larger files, a fallback HTTP server. The campaign operator alternately used GitHub, PyPI , and Mapbox, several of which were created with leaked or stolen credentials. The campaign has not been attributed to any known threat group.
See also: Google Ads: Fake “Claude” site leads to ACR Stealer infection

ChocoPoC: The seven fake PoC repos and the targeted CVEs
Sekoia and YesWeHack identified at least seven fake PoC repositories , each associated with a high-profile vulnerability: CVE -2025-64446 (FortiWeb path traversal), CVE-2025-55182 (React2Shell), CVE-2025-14847 (MongoBleed), CVE-2026-0257 (PAN-OS auth bypass), CVE-2026-10520 (Ivanti Sentry command injection), CVE-2026-50751 (Check Point VPN auth bypass), and CVE-2026-48908 (Joomla SP Page Builder RCE). The skytext package alone was recorded about 2,400 times , mostly on Linux systems , with spikes immediately after major CVEs were made public — an indication that the campaign acts as a trap for researchers rushing to test new exploits.
An earlier version of the same campaign, dating back to late 2025 , used two other packages, slogsec and logcrypt.cryptography , with nearly identical code. Sekoia estimates with high confidence that the same actor is behind both campaigns, based on reused audit trails. This is not the first incident to target security researchers via fake PoCs: the MUT-1244 campaign had used a similar technique to steal SSH keys and cloud credentials from red teamers , while the North Korean Lazarus group has targeted researchers repeatedly since 2021 , distributing malicious Visual Studio projects and exploiting zero-day vulnerabilities.
See also: New Miasma campaign targets npm packages and GitHub Actions

Security researchers are a particularly attractive target: they run untrusted code by nature, often with high privileges, and their machines contain customer credentials, private reports, and active assignment details. A researcher’s compromise could lead to access far beyond a single laptop. To protect against ChocoPoC and similar threats, experts recommend: verifying PoC repositories from trusted sources before execution, auditing all PyPI dependencies with tools like pip-audit or safety, isolating research environments in VMs without access to sensitive data, and monitoring outbound traffic to Mapbox APIs unless it is essential for business operations. ChocoPoC remains active, and the security community is urged to exercise caution with any PoC repositories claiming to exploit newly disclosed vulnerabilities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
