Summary
A new data-stealing malware dubbed ChocoPoC is actively targeting vulnerability researchers by hiding in fake proof-of-concept exploit repositories on GitHub. Discovered jointly by YesWeHack and Sekoia on July 1, 2026, the malware operates as a Remote Access Trojan that steals credentials, browser data, and provides persistent shell access to infected systems.
Unlike typical trojanized PoCs, ChocoPoC doesn’t embed malicious code directly in the exploit script. Instead, it hides within seemingly legitimate Python dependencies — packages named “frint” and “skytext” listed in the PoC’s requirements. When researchers clone a repo and run pip install -r requirements.txt, the malicious packages are pulled from PyPI. The “skytext” package contains a compiled native extension that downloads the final ChocoPoC payload on execution.
At least seven fake PoC repositories have been identified, each targeting high-profile CVEs in FortiWeb, PAN-OS, Ivanti Sentry, Check Point VPN, and other products. The “skytext” package alone has been downloaded approximately 2,400 times, primarily on Linux systems. The malware’s C2 infrastructure remains active as of July 2.
Sources
Commentary
This is a clever evolution of the trojanized-PoC attack vector. By hiding the payload in pip dependencies rather than the exploit code itself, the attackers are betting that researchers will scrutinize the PoC script but skip auditing the packages it pulls in — and they’re right. Most researchers instinctively review the main Python file but treat requirements.txt as trustworthy plumbing.
The targeting is also surgical: vulnerability researchers are high-value targets because their workstations often contain unpublished exploits, access to bug bounty platforms, VPN credentials to client networks, and communications with vendors about unpatched flaws. If you do exploit research, this is your reminder to run every PoC in a disposable VM or container — no exceptions. And audit those dependencies.
