Trojanized GitHub exploit repositories used malicious PyPI packages to install ChocoPoC remote-access malware

Attackers hid malware in GitHub proof-of-concept exploit repositories and infected people who cloned and ran them. Sekoia says at least seven repositories for exploits tied to FortiWeb CVE-2025-64446, React2Shell CVE-2025-55182, MongoBleed CVE-2025-14847, PAN-OS CVE-2026-0257, Ivanti Sentry CVE-2026-10520, Check Point VPN CVE-2026-50751, and Joomla SP Page Builder CVE-2026-48908 pulled malicious PyPI packages including frint and skytext, which installed the ChocoPoC RAT, a remote-access trojan that can run commands and steal credentials and files.
Why it matters: This targets the very people trying to test or defend against vulnerabilities, and it can silently hand over passwords, browser sessions, files, and system access. Anyone who cloned untrusted exploit code from GitHub should review systems for the listed packages and treat such testing as high-risk unless done in isolated environments.

Sources

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos
info@thehackernews.com (The Hacker News) 2026.07.02 97% relevant
This article appears to cover the same ChocoPoC campaign: attackers used fake exploit or proof-of-concept GitHub repositories to target security researchers and deliver the ChocoPoC remote-access trojan, adding reporting detail about the victim profile and lure theme.
ChocoPoc malware delivered via trojanized exploits on GitHub
Bill Toulas 2026.07.01 100% relevant
This article establishes a distinct malware-delivery campaign centered on trojanized exploit repositories and malicious Python dependencies, not a previously tracked single CVE or vendor patch event.
New ChocoPoC malware targets researchers via trojanized PoC exploits
Bill Toulas 2026.07.01 99% relevant
This article covers the same ChocoPoC campaign and adds reporting details on the frint and skytext PyPI packages, the Mapbox-hosted payload delivery and exfiltration path, the list of seven themed PoC repositories, and evidence the attackers likely used compromised accounts tied to earlier 2025 trojanized-PoC activity.
← Back to all stories