Don't Eat the ChocoPoCs: Trojanised PoCs Hit Researchers
ID: bd52f5d3-35fb-510f-80f3-9661b1d934d3
STIX ID: report--bd52f5d3-35fb-510f-80f3-9661b1d934d3
Feed Name: Sekoia.com
YesWeHack and Sekoia TDR analyze an active supply-chain campaign that lures vulnerability researchers and pentesters with malicious PoC repositories and PyPI dependencies (notably frint and skytext) to install a Python RAT dubbed ChocoPoC; the RAT is delivered via compiled native extensions, retrieves additional stages from Mapbox datasets using DoH and Host-header/SNI fronting, and exfiltrates credentials, cookies, and files. The report provides a full infection chain, technical analysis of the native loader and persistence mechanisms, multiple IoCs (package and binary SHA-256s, GitHub repos, Mapbox dataset/feature and tokens, C2 IP), evidence of account reuse/compromise, and indicators of multiple related campaigns across 2025–2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
