New ChocoPoC RAT Hides in Fake PoC Repositories

Researchers Uncover a New Malware Campaign

New ChocoPoC RAT is targeting vulnerability researchers through fake proof-of-concept repositories. Attackers disguise the malware inside exploit code for newly disclosed security flaws. As a result, researchers may infect their own systems while testing vulnerabilities. Therefore, this campaign creates serious risks for cybersecurity professionals.

Researchers found that the malware steals sensitive information after execution. Moreover, it allows attackers to control the infected computer remotely. The campaign remained active when researchers published their findings. Therefore, experts advised users to avoid running suspicious PoC repositories.

Malware Hides Inside Software Dependencies

The visible exploit code appears harmless during a quick review. However, the malware hides inside a Python dependency downloaded during installation. As a result, many users may overlook the real threat. This technique helps attackers avoid simple code inspections.

The infection starts when users install the required packages. Next, one package silently downloads another hidden component. Moreover, that component waits until the real PoC file starts running. Therefore, many security sandboxes fail to detect the malware because it stays inactive.

ChocoPoC Steals Valuable Information

Once activated, New ChocoPoC RAT collects many types of sensitive data. For example, it steals saved passwords, browser cookies, browsing history, and autofill information. It also searches for text files, databases, and command history. Consequently, attackers gain access to valuable personal and business information.

The malware also gives attackers remote control over the infected device. Therefore, they can execute commands and download additional files. Moreover, they can run custom Python code and manage stolen data remotely. This flexibility makes the malware highly dangerous.

Attackers Hide Their Communications

Researchers found that the malware disguises its network traffic. Instead of contacting suspicious servers directly, it uses trusted online services. Consequently, security tools may view the traffic as normal activity. This approach helps attackers avoid detection.

The malware also uses additional techniques to hide its communication. For example, it relies on encrypted DNS requests and traffic masking. Therefore, investigators face greater challenges during analysis. These methods increase the campaign’s effectiveness.

Fake PoC Repositories Continue to Spread

Researchers identified several fake repositories connected to popular software vulnerabilities. These repositories appeared shortly after high-profile security flaws became public. Moreover, attackers focused on vulnerabilities that attracted immediate attention. Therefore, they increased the chance that researchers would download the files.

The malicious packages received thousands of downloads. However, download numbers do not confirm successful infections. Researchers also linked the campaign to earlier malicious packages with similar code. As a result, they believe one threat actor operates the entire campaign.

Cybersecurity Researchers Face Greater Risks

Security researchers often execute unknown code during investigations. Therefore, attackers see them as valuable targets. Their systems frequently contain confidential reports, customer information, and security credentials. Consequently, a single compromise may expose many organizations.

Researchers also noted that similar attacks have happened before. However, New ChocoPoC RAT introduces a new delivery method. Instead of hiding inside the visible exploit, the malware hides inside dependencies. This change makes detection much more difficult.

How to Prevent New ChocoPoC RAT Attacks

Organizations should verify every proof-of-concept repository before testing unknown code. Moreover, researchers should review every dependency instead of checking only the main files. Running suspicious code inside isolated environments also reduces potential damage.

In addition, managed detection and response services help identify unusual activity quickly, while regular security awareness training teaches employees how to recognize fake repositories and supply chain threats before they cause harm.

Sleep well, we got you covered.

Scroll to Top