ChocoPoC RAT Hides in Fake GitHub Exploits, Targets Security Researchers

A cluster of trojanized proof-of-concept repositories is pushing a Python-based remote access trojan to the very people who go looking for them.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: a cluttered security researcher's desk at night: open laptop showing terminal-
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Multiple GitHub repositories posing as proof-of-concept exploits are delivering a Python-based remote access trojan named ChocoPoC.
  • The targets are cybersecurity researchers: vulnerability analysts, red teamers, malware reversers.
  • The RAT fingerprints the host, opens a command channel, and steals browser data and SSH keys.
  • Operators reused commit patterns and README boilerplate across accounts, which is how the cluster was identified.
  • GitHub has removed flagged repositories, but new accounts keep appearing.

What is ChocoPoC and who is behind it?

ChocoPoC is a Python-based remote access trojan (RAT, malware that gives an attacker remote control of an infected machine) delivered through GitHub repositories that advertise working exploits for high-severity CVEs. The operators are unattributed. They behave more like an access-and-collection outfit than a ransomware crew: build credibility on GitHub, wait for researchers to clone the repos, harvest whatever lands. Similar tradecraft was used against researchers in the North Korea-linked social engineering campaign Google TAG flagged in 2021. We first reported on ChocoPoC on 1 July 2026.

How does the infection work?

The lure is the payload. Repositories advertise PoCs for recent, high-CVSS CVEs (vulnerability scores that rank severity out of ten), the kind researchers clone reflexively. Buried in the Python source is a loader that pulls ChocoPoC from a remote host. Once running, the RAT fingerprints the machine, opens a command channel, supports arbitrary shell execution, and steals browser data and SSH keys, filtering for files matching researcher-flavored keywords. Exfiltration runs over HTTPS to attacker infrastructure on commodity hosting. Several repos had non-trivial star counts and forks before takedown, which suggests real victims ran the code.

Why target researchers specifically?

There's no ransom here, no leak site, no negotiation portal. The economics look closer to espionage or resale to an initial access broker than to extortion. A stolen SSH key or browser session from a working researcher becomes a foothold at whichever vendor or bug bounty program that researcher touches next. The researcher is the bridge.

Should you worry if you clone public exploit code?

Yes, and the precautions are straightforward. Detonate in a disposable VM with no persistent credentials and egress logging on. Read setup.py, __init__.py, and requirements.txt before running pip install, malicious dependencies are a common second stage, something GitHub's npm overhaul in June 2026 was partly designed to address. Rotate any credentials that touched a machine which ran an untrusted PoC in the last 90 days. Defenders running detonation pipelines against public PoCs should treat unsigned Python that reaches out on import as hostile.

Indicators shared so far include GitHub handles pushing near-identical PoC scaffolding and C2 domains registered within days of the repos going live. Expect the campaign to rebrand rather than retire.

The thing worth watching is the pivot point: the researchers being targeted here aren't the final target. They're the access.

© 2026 Threat Vectr