MalwareBleeping Computer
10.0 — CRITICAL
New ChocoPoC malware targets researchers via trojanized PoC exploits
Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
Researchers have discovered a new malware campaign, ChocoPoC, that targets cybersecurity researchers via trojanized PoC exploits on GitHub, utilizing a novel delivery mechanism involving malicious Python packages hosted on PyPI.
⚙️Technical Details
Attack Vectors
NETWORKNETWORKNETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Cybersecurity researchers and vulnerability testers
🛡️Recommended Actions
1Never blindly trust GitHub repositories and only execute unverified code in isolated environments.
2Regularly update software and systems with the latest security patches.
3Monitor system logs for suspicious activity and implement robust security monitoring.
📦Affected Products
Fortinet FortiwebFacebook ReactVercel Next.JsMongodb MongodbPaloaltonetworks Pan-OsPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808Siemens Ruggedcom Ape1808 FirmwareIvanti Standalone SentryFortinet FortiWeb
🔐NVD Verified DataVERIFIED
CVE-2025-64446 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-23
Affected Products (CPE)
Fortinet Fortiweb
CVE-2025-55182 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-502
Affected Products (CPE)
Facebook ReactVercel Next.Js
CVE-2025-14847 ↗CVSS 7.5 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NWeaknesses
CWE-130
Affected Products (CPE)
Mongodb Mongodb
CVE-2026-0257 ↗CVSS 9.1 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NWeaknesses
CWE-565
Affected Products (CPE)
Paloaltonetworks Pan-OsPaloaltonetworks Prisma AccessSiemens Ruggedcom Ape1808Siemens Ruggedcom Ape1808 Firmware
CVE-2026-10520 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-78
Affected Products (CPE)
Ivanti Standalone Sentry
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
