Don't Eat the ChocoPoCs: Trojanised PoCs Hit Researchers
Sekoia TDR and YesWeHack disclosed a sophisticated supply-chain attack targeting vulnerability researchers via trojanised PoC repositories on GitHub. Malicious Python packages (frint/skytext) deliver ChocoPoC, a fully-featured Python RAT with anti-analysis capabilities, credential harvesting, and C2 via Mapbox dead-drop infrastructure. At least 7 fake CVE PoC repos identified since late 2025, exploiting researcher urgency to test new vulnerabilities.