ChocoPoC is a Python-based remote access trojan used in a supply-chain style campaign that targets vulnerability researchers, penetration testers, and other security practitioners through trojanized proof-of-concept exploit repositories. The malware is typically delivered through fake GitHub repositories themed around newly disclosed CVEs, where the visible exploit code appears benign but the dependency chain installs malicious Python packages that unpack and launch the RAT through compiled native extensions on Windows and Linux. The payload is designed to activate only in the expected proof-of-concept runtime context, which helps it evade superficial code review and simple sandbox detonation.
Once active, ChocoPoC combines RAT and infostealer functionality. It can execute arbitrary shell commands and Python code, retrieve files and directories from the victim host, and collect system information including command history, running processes, network configuration, and host details. It also steals browser data from Chrome, Brave, Edge, and Firefox, including saved passwords, cookies, autofill data, browsing history, and related profile information. Observed collection behavior also includes searching for local text and database files.
The malware uses multiple stealth and resilience techniques. Reported tradecraft includes persistence through Python startup mechanisms, anti-debugging checks, environmental gating tied to exploit-themed filenames, and timestomping. For command retrieval and concealment, ChocoPoC abuses Mapbox-hosted data as a dead-drop channel and uses DNS-over-HTTPS and domain fronting so traffic resembles legitimate mapping-service requests. Related activity has been linked to earlier malicious package waves using similar code and infrastructure patterns, indicating an ongoing campaign active since at least late 2025. The operation has been associated with fake repositories impersonating exploit code for high-profile enterprise and internet-facing products, with the apparent objective of compromising researcher workstations and harvesting credentials, sessions, and sensitive research data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Эксперты обнаружили как минимум семь фейковых репозиториев, которые якобы содержали эксплоиты для уязвимостей FortiWeb (CVE-2025-64446)... | При запуске такие эксплоиты устанавливают в систему жертвы RAT ChocoPoC, который ворует пароли, файлы и данные из браузеров, а затем предоставляет своим операторам удаленный доступ к зараженной машине.
Эксперты обнаружили как минимум семь фейковых репозиториев, которые якобы содержали эксплоиты для уязвимостей ... PAN-OS (CVE-2026-0257) ... | При запуске такие эксплоиты устанавливают в систему жертвы RAT ChocoPoC, который ворует пароли, файлы и данные из браузеров, а затем предоставляет своим операторам удаленный доступ к зараженной машине.
Эксперты обнаружили как минимум семь фейковых репозиториев, которые якобы содержали эксплоиты для уязвимостей ... Check Point VPN (CVE-2026-50751) ... | При запуске такие эксплоиты устанавливают в систему жертвы RAT ChocoPoC, который ворует пароли, файлы и данные из браузеров, а затем предоставляет своим операторам удаленный доступ к зараженной машине.
Эксперты обнаружили как минимум семь фейковых репозиториев, которые якобы содержали эксплоиты для уязвимостей ... React2Shell (CVE-2025-55182) ... | При запуске такие эксплоиты устанавливают в систему жертвы RAT ChocoPoC, который ворует пароли, файлы и данные из браузеров, а затем предоставляет своим операторам удаленный доступ к зараженной машине.
Эксперты обнаружили как минимум семь фейковых репозиториев, которые якобы содержали эксплоиты для уязвимостей ... MongoBleed (CVE-2025-14847) ... | При запуске такие эксплоиты устанавливают в систему жертвы RAT ChocoPoC, который ворует пароли, файлы и данные из браузеров, а затем предоставляет своим операторам удаленный доступ к зараженной машине.
Эксперты обнаружили как минимум семь фейковых репозиториев, которые якобы содержали эксплоиты для уязвимостей ... Joomla SP Page Builder (CVE-2026-48908). | При запуске такие эксплоиты устанавливают в систему жертвы RAT ChocoPoC, который ворует пароли, файлы и данные из браузеров, а затем предоставляет своим операторам удаленный доступ к зараженной машине.
Эксперты обнаружили как минимум семь фейковых репозиториев, которые якобы содержали эксплоиты для уязвимостей ... Ivanti Sentry (CVE-2026-10520) ... | При запуске такие эксплоиты устанавливают в систему жертвы RAT ChocoPoC, который ворует пароли, файлы и данные из браузеров, а затем предоставляет своим операторам удаленный доступ к зараженной машине.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
skytext ships a compiled native extension named gradient.pyd on Windows and gradient.so on Linux. That native extension runs when the PoC is executed.
извлекает сохраненные пароли, cookie, данные автозаполнения и историю из браузеров Chrome, Brave, Edge и Firefox
использует domain fronting, поэтому трафик выглядит как обычные обращения к API Mapbox
For command retrieval, the downloader abuses Mapbox API traffic as a dead-drop channel
После этого происходит распаковка пейлоада и загружается сам ChocoPoC
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a previously covered malware family delivered through fake proof-of-concept repositories.
Remote access trojan delivered via fake GitHub PoC exploit repositories and malicious Python dependency chains. It steals saved passwords, cookies, autofill data, browser history, text files, notes, local databases, shell history, network settings, and process lists, while also allowing operators to execute arbitrary commands and Python code, download directories, and pause activity for stealth.
Remote access trojan delivered through trojanized PoC repositories and malicious PyPI dependencies. It performs file exfiltration, steals browser credentials and cookies, collects system information, executes arbitrary commands, adjusts beacon timing, and exfiltrates data over HTTP and via Mapbox datasets while masking C2 with DoH and domain fronting.
A data-stealing trojan distributed via fake Python PoC repositories on GitHub. It hides in malicious package dependencies, steals saved passwords, browser cookies, files, shell history, and network settings, can execute arbitrary shell commands, and uses domain fronting to make C2 traffic resemble legitimate Mapbox API calls.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.