Dettaglio notizia
| Data | 03/07/2026 |
| Titolo | ChocoPoC RAT Spread Through Trojanized GitHub PoC Exploit Repositories |
| Contesto | A malware campaign dubbed ChocoPoC used fake or trojanized GitHub proof-of-concept exploit repositories for newly disclosed CVEs to infect cybersecurity researchers, penetration testers, and bug hunters. Researchers at Sekoia and YesWeHack said the visible exploit code often appeared benign, while the real payload was introduced through malicious PyPI dependencies including frint and skytext. The package chain decrypted and executed code that fetched the final Python-based remote access trojan from a Mapbox dataset, and investigators linked at least seven repositories to the operation. The activity appears to have relied largely on compromised accounts to publish the poisoned packages and repositories, with skytext alone drawing roughly 2,400 downloads, mostly on Linux systems.Once activated, ChocoPoC provided remote shell and Python execution, stole browser credentials and files, uploaded data, enumerated processes, and collected host details such as network configuration and shell history. The malware was designed to evade casual review and simple sandboxing by delaying activation until the PoC was run, while also using DNS-over-HTTPS to resolve infrastructure and 91.132.163.78 for larger uploads. Investigators said related activity may date back to late 2025 through earlier packages such as slogsec and logcrypt.cryptography, raising concern that compromises of researcher workstations could create downstream supply-chain risk for trusted security tooling and frameworks. |
| Fonte | https://mallory.ai/stories/019f1f86-22f7-7331-8f9c-27cd301ce16f |
| Discussione? | Parliamone sul Forum |