FeedMalwareNew ChocoPoC malware targets researchers via trojanized PoC ...
MalwareBleeping Computer
10.0CRITICAL

New ChocoPoC malware targets researchers via trojanized PoC exploits

📅 1 July 2026 at 20:08 UTC📰 Bleeping ComputerView original source ↗
New ChocoPoC malware targets researchers via trojanized PoC exploits

Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Researchers have discovered a new malware campaign, ChocoPoC, that targets cybersecurity researchers via trojanized PoC exploits on GitHub, utilizing a novel delivery mechanism involving malicious Python packages hosted on PyPI.

⚙️Technical Details
Attack Vectors
NETWORKNETWORKNETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Cybersecurity researchers and vulnerability testers
🛡️Recommended Actions
1Never blindly trust GitHub repositories and only execute unverified code in isolated environments.
2Regularly update software and systems with the latest security patches.
3Monitor system logs for suspicious activity and implement robust security monitoring.
📦Affected Products
Fortinet FortiwebFacebook ReactVercel Next.JsMongodb MongodbPaloaltonetworks Pan-OsPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808Siemens Ruggedcom Ape1808 FirmwareIvanti Standalone SentryFortinet FortiWeb
🔐NVD Verified DataVERIFIED
CVE-2025-64446CVSS 9.8CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-23
Affected Products (CPE)
Fortinet Fortiweb
CVE-2025-14847CVSS 7.5HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-130
Affected Products (CPE)
Mongodb Mongodb
CVE-2026-0257CVSS 9.1CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-565
Affected Products (CPE)
Paloaltonetworks Pan-OsPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808Siemens Ruggedcom Ape1808 Firmware
CVE-2026-10520CVSS 10CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-78
Affected Products (CPE)
Ivanti Standalone Sentry

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed