#ChocoPoC
CEREALES "EL CHOCOPOC":
TE CORRERÁS DE LA RISA
November 9, 2024 at 11:09 AM
OY TODAS LAS UMIDADES DE CHOCOPOC' ESTARAN ASTA UN 50% MAS CARAS (STRATEGIA DE MARKETLNG PARA GANAR YO MAS DINERO)
November 28, 2025 at 8:04 AM
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
thehackernews.com
July 2, 2026 at 8:02 AM
Multiple weaponized proof-of-concept (PoC) exploits on GitHub delivered a Python-based remote access trojan (RAT) called ChocoPoC that can execute commands and steal sensitive data.
ChocoPoc malware delivered via trojanized exploits on GitHub
Multiple weaponized proof-of-concept (PoC) exploits on GitHub delivered a Python-based remote access trojan (RAT) called ChocoPoC that can execute commands and steal sensitive data.
www.bleepingcomputer.com
July 1, 2026 at 8:08 PM
July 2, 2026 at 5:17 AM
📰 Malware ChocoPoC Menyusup Lewat PoC Palsu di GitHub, Targetkan Peneliti Keamanan Siber

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/07/05/malware-chocopoc-serang-peneliti-keamanan-lewat-poc-github/

#cho
co#chocopocr#cybersecurityo#exploitu#githuba#malwaret#penetrationTesting #pypi
July 5, 2026 at 3:49 PM
- Chocopocs, Chocopoc, Chocu, El Hipopótamo Juan, La Jirafa Nosequé y el Camaleón Italiano son propiedades creadas por los CREADO POR LOS AUTORES.
- Al compartir o gustar los posts, el USUARIO garantiza BAJO JURAMENTO compartir los hechos e ideas que en ellos se describen.
September 12, 2023 at 1:04 PM
ChocoPoC: Wie manipulierte Exploit-Repositories auf GitHub Zugangsdaten von Sicherheitsforschern abgreifen - Über präparierte GitHub-Repositories mit vermeintlichen CVE-Exploits schleusen sie eine Schadsoftware namens ChocoPoC ein, die..
www.all-about-security.de/chocopoc-wie...

#GitHub #malware
ChocoPoC: Malware in GitHub-Exploits analysiert
Erfahren Sie, wie ChocoPoC in GitHub-Repositories verteilt wird und Sicherheitsforscher möglicherweise gefährdet.
www.all-about-security.de
July 2, 2026 at 8:23 AM
📰 Malware ChocoPoC Sebar Trojan Lewat PoC Palsu di GitHub, Peneliti Keamanan Jadi Target Utama

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/07/02/chocopoc-malware-poc-palsu-github/

#cho
co#chocopocr#cybersecurityu#githuba#malwaref#proofOfConcept #pypio#pythont#remoteAccessTrojan#vuln
July 2, 2026 at 3:35 AM
New ChocoPoC trojan targets security researchers with fake exploit code

www.scworld.com/brief/new-ch...

#Cybersecurity #Tietomurto
New ChocoPoC trojan targets security researchers with fake exploit code
ChocoPoC operates by hiding its malicious payload within a Python package that is pulled in as a dependency by the seemingly harmless PoC code.
www.scworld.com
July 2, 2026 at 7:34 PM
Fake Python PoC repos are hiding ChocoPoC RAT, which reaches security researchers via malicious dependencies, then steals browser creds, files, autofill data, and shell history while using Mapbox and DNS-over-HT. #ChocoPoC #GitHub #Python
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Attackers are hiding the ChocoPoC data-stealing trojan inside fake Python exploit repositories that target security researchers rushing to test new CVEs. The malware steals browser credentials and files, then uses dependency chains, Mapbox, and other infrastructure to stay hidden while spreading through malicious PoCs. #ChocoPoC #YesWeHack #Sekoia #Mapbox #GitHub #PyPI...
www.hendryadrian.com
July 2, 2026 at 9:15 AM
-New ChocoPoC, TONResolver RAT, and BeepRAT
-The Gentlemen ransomware abuses a zero-day to disable EDRs
-New ARToken phishing kit
-Roska Bridge info-op active on Mastodon and BlueSky
-Apple Hide My Email bug exposes email addresses
-New InkJect attack
-DuneSlide vulns
July 3, 2026 at 8:57 AM
New ChocoPoC malware targets researchers via trojanized PoC exploits

Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign belie…
#hackernews #news
New ChocoPoC malware targets researchers via trojanized PoC exploits
Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers. [...]
www.bleepingcomputer.com
July 2, 2026 at 9:10 PM
ChocoPoC: RAT nascosto in repo GitHub di PoC exploit (FortiWeb, PAN-OS, Check Point VPN). La dipendenza pip installata per testare l'exploit ruba credenziali e browser data, C2 via Mapbox dead-drop. Almeno 7 repo ancora attivi. Isola sempre i PoC in sandbox.
#ThreatIntel #RedTeam
July 6, 2026 at 8:50 PM
Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC)...

🔗 https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html
July 2, 2026 at 10:25 AM
🚨 Alerta: Detectada una campaña que utiliza repositorios falsos de PoCs (pruebas de concepto) para infectar con 'ChocoPoC', un troyano (RAT) en Python altamente sofisticado. 🐍💀
​https://thehackernews.com/2026/07/new-chocopoc-rat-targets-vulnerability.html

​#Cybersecurity #Infosec #Malware
New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
Fake CVE exploit repos pull frint and skytext packages to steal researcher credentials, with servers still live as of July 1.
thehackernews.com
July 2, 2026 at 8:26 AM
Cybersecurity researchers are being targeted by a new Python RAT called 'ChocoPoC.' The malware is hidden in weaponized proof-of-concept exploits on GitHub, turning researchers' own tools against them. 🐍 #Malware #CyberSecurity #GitHub #ThreatIntel

🌐 cyber[.]netsecops[.]io
'ChocoPoC' Malware Campaign Targets Cybersecurity Researchers with Trojanized GitHub Exploits
A new malware campaign, ChocoPoC, is targeting security researchers by distributing a Python RAT through trojanized proof-of-concept exploits hosted on GitHub.
cyber.netsecops.io
July 10, 2026 at 3:56 PM
The irony is brutal: ChocoPoC malware is turning open-source PoC exploits into a weapon against security researchers. This supply chain attack leverages GitHub and PyPI, making your own tools a risk. Learn how it works and protect…

https://www.tpp.blog/22d4axc

#cybersecurity #chocopoc #sekoia
July 2, 2026 at 4:13 AM
New malware called ChocoPoC hides in fake exploit code on GitHub and steals the credentials of researchers who run it.

The payload sits in a Python dependency, not the exploit script.

Test PoCs in a throwaway, credential-free VM.
Fake exploit code is delivering ChocoPoC, a stealer aimed at the researchers who run it
ChocoPoC hides a credential-stealing trojan inside fake CVE proof-of-concept repos, targeting the researchers and red teams who download and test them.
suriq.io
July 2, 2026 at 11:52 AM
Researchers were targeted by ChocoPoC, a Python RAT hidden in fake CVE PoC repos and malicious PyPI deps. At least 7 lures abused GitHub, PyPI, and Mapbox to steal data and persist in Python envs. #ChocoPoC #PyPI #GitHub
Don’t Eat The ChocoPoCs! How Vulnerability Researchers Were Repeatedly Targeted By Trojanised Exploits
YesWeHack and Sekoia TDR uncovered ChocoPoC, a Python RAT hidden in fake CVE PoC repositories and malicious PyPI dependencies used to target vulnerability researchers and pentesters. The campaign abused GitHub, PyPI, and Mapbox infrastructure to deliver payloads, persist in Python environments, and steal data, with at least 7 lure repositories identified and the malware still active. #ChocoPoC #YesWeHack #SekoiaTDR #Mapbox #frint #skytext
www.hendryadrian.com
July 4, 2026 at 6:30 AM
ChocoPocマルウェア、GitHub上のトロイの木馬化されたエクスプロイトから配布

GitHub上に存在する複数の武器化された概念実証(PoC)エクスプロイトが、コマンド実行や機密データの窃取が可能なPythonベースのリモートアクセス型トロイの木馬(RAT)「ChocoPoC」を配布していたことが分かりました。 各種脆弱性向けのPoCエクスプロイトにマルウェアを隠す手口自体は目新しいものではありま...
ChocoPocマルウェア、GitHub上のトロイの木馬化されたエクスプロイトから配布
GitHub上に存在する複数の武器化された概念実証(PoC)エクスプロイトが、コマンド実行や機密データの窃取が可能なPythonベースのリモートアクセス型トロイの木馬(RAT)「ChocoPoC」を配布していたことが分かりました。 各種脆弱性向けのPoCエクスプロイトにマルウェアを隠す手口自体は目新しいものではありま
blackhatnews.tokyo
July 1, 2026 at 8:15 PM
ChocoPoC Crisis: How a Tasty-Looking Joomla PoC Became a Full-Blown Supply Chain Attack + Video

Introduction: In late June 2026, YesWeHack’s vulnerability intelligence team published an analysis of a critical unauthenticated RCE flaw in the Joomla JCE extension (CVE-2026-48907), including a…
ChocoPoC Crisis: How a Tasty-Looking Joomla PoC Became a Full-Blown Supply Chain Attack + Video
Introduction: In late June 2026, YesWeHack’s vulnerability intelligence team published an analysis of a critical unauthenticated RCE flaw in the Joomla JCE extension (CVE-2026-48907), including a proof-of-concept (PoC) and a Nuclei template. Within days, an attacker leveraged that very research to launch a sophisticated social‑engineering campaign. Posing as a contributor, they submitted two supposed PoCs for a related Joomla vulnerability—one of which contained a previously undocumented, fully functional Python RAT dubbed “ChocoPoC”.
undercodetesting.com
July 2, 2026 at 12:49 AM
🟢 ChocoPoC Malware Spreads Disguised as Fake Exploits

🗨️ Experts from YesWeHack and Sekoia have discovered a malicious campaign targeting cybersecurity researchers: attackers ar…

#news
ChocoPoC Malware Spreads Disguised as Fake Exploits
Read more
hackmag.com
July 13, 2026 at 9:00 PM