{"id":1139,"date":"2026-08-19T20:25:47","date_gmt":"2026-08-19T14:55:47","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1139"},"modified":"2026-08-19T20:26:14","modified_gmt":"2026-08-19T14:56:14","slug":"chocopoc-malware-trojanized-poc-exploits","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/","title":{"rendered":"ChocoPoC Malware: Trojanized GitHub Exploits Target Security Researchers"},"content":{"rendered":"<p>A newly discovered malware campaign, ChocoPoC, highlights a growing risk in modern vulnerability research: public proof-of-concept (PoC) exploits can themselves become the attack vector. Rather than compromising the exploit code directly, the campaign weaponized the software supply chain by introducing malicious Python package dependencies into GitHub-hosted PoC repositories.<\/p>\n<p>For enterprise security teams, vulnerability validation is a routine part of defensive operations. But when PoCs are cloned and executed without verifying their dependencies, researcher workstations and lab systems can become entry points for credential theft, remote access, and broader network compromise. ChocoPoC serves as a reminder that even trusted security workflows require the same level of scrutiny applied to production software.<\/p>\n<h2>Breaking Down the ChocoPoC Attack<\/h2>\n<p>The ChocoPoC infection chain exploits a workflow that many security professionals use every day: cloning and running public proof-of-concept (PoC) repositories. Instead of embedding malicious code in the exploit itself, the attackers weaponize the PoC&#8217;s Python dependency chain. This makes the compromise much harder to detect during routine code reviews.<\/p>\n<p>When a victim clones and runs a trojanized repository, a malicious Python package named frint is installed. The package then retrieves another package called skytext. During execution, a compiled native Python extension decrypts additional code. It then downloads the final ChocoPoC remote access trojan (RAT) payload from data hosted on Mapbox.<\/p>\n<p>Once deployed, the malware provides attackers with a broad set of post-compromise capabilities, including:<\/p>\n<ul>\n<li>Remote command execution through shell and Python commands.<\/li>\n<li>File and directory uploads from the compromised system.<\/li>\n<li>Theft of browser credentials, cookies, and other locally stored data.<\/li>\n<li>Collection of shell history, network configuration, and system information.<\/li>\n<li>Process enumeration and local file discovery to support further reconnaissance.<\/li>\n<li>Data exfiltration and additional attacker-controlled operations.<\/li>\n<\/ul>\n<p>This dependency-based attack is particularly effective because the exploit code itself may appear legitimate during a quick source review. Security researchers who focus only on the PoC source while overlooking its package dependencies may inadvertently execute malicious code as part of the normal installation process.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/evaluate-xdr-vendor.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>How to Evaluate an XDR Vendor for Your Security Stack<\/h4><p>Choose an XDR vendor that delivers true visibility, smart correlation, and rapid response\u2014not just marketing claims.https:\/\/www.hexnode.com\/blogs\/eval<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/evaluate-xdr-vendor\/\" aria-label=\"How to Evaluate an XDR Vendor for Your Security Stack\"><\/a><\/div><\/div><\/div><\/p>\n<h2>How Hexnode Helps Reduce the Risk<\/h2>\n<p>While organizations cannot control the integrity of public PoC repositories, they can reduce the impact of a compromised research workstation by enforcing consistent endpoint security policies.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\" rel=\"noopener\">Hexnode UEM<\/a> helps IT teams strengthen researcher and administrator devices by enabling:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/uem\/features\/patch-and-update-management\/\" rel=\"noopener\">Patch management<\/a> to reduce exposure to known vulnerabilities.<\/li>\n<li>Application management to restrict unauthorized or unapproved software.<\/li>\n<li>Device encryption enforcement to protect sensitive data at rest.<\/li>\n<li><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/compliance\/\" rel=\"noopener\">Compliance policies<\/a> that continuously verify devices meet organizational security requirements before they access enterprise resources.<\/li>\n<\/ul>\n<p>When suspicious activity is detected on a device used for vulnerability research or testing, security teams can use Hexnode&#8217;s remote device management capabilities to take remediation actions, such as locking or wiping a compromised endpoint, helping contain the incident and reduce the potential impact on the broader enterprise environment.<\/p>\n<p>Combined with enterprise endpoint detection and response (EDR\/XDR) tooling, these controls help organizations limit the risk posed by trojanized PoCs by reducing the attack surface, enforcing endpoint hygiene, and enabling faster incident response.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/infographic_UEM-Blackbelt.webp?format=webp\" class=\"resource-box__image\" alt=\"infographic_UEM-Blackbelt\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/infographic_UEM-Blackbelt.webp?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/infographic_UEM-Blackbelt-300x225.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/infographic_UEM-Blackbelt-768x576.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/infographic_UEM-Blackbelt-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"infographic_UEM-Blackbelt\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Becoming a UEM blackbelt\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Explore how Hexnode helps you master UEM\u2014one belt at a time, from enrollment to automation.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/becoming-a-uem-blackbelt\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>Conclusion<\/h2>\n<p>The ChocoPoC campaign reinforces an important lesson for enterprise security teams: public exploit code should be treated as untrusted software. Even when a PoC originates from a seemingly legitimate repository, its dependencies and execution chain can introduce significant risk to researcher workstations and, by extension, the broader enterprise environment.<\/p>\n<p>To reduce that risk, organizations should adopt a layered approach that includes:<\/p>\n<ul>\n<li>Isolated testing environments for evaluating public PoCs.<\/li>\n<li>Continuous endpoint monitoring to detect anomalous activity during exploit testing.<\/li>\n<li>Strict device compliance policies to ensure research systems adhere to security baselines.<\/li>\n<li>Dependency verification before installing packages or executing third-party code.<\/li>\n<\/ul>\n<p>As software supply chain attacks continue to evolve, securing the tools and workflows used for vulnerability research is just as important as defending production systems.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try Hexnode free for 14 days<\/h5><p>Secure every endpoint before threats spread. See how Hexnode helps enforce enterprise-ready endpoint security.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A newly discovered malware campaign, ChocoPoC, highlights a growing risk in modern vulnerability research: public&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1140,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,15],"class_list":["post-1139","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-malware","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ChocoPoC Malware: Trojanized GitHub Exploits Target Security Researchers<\/title>\n<meta name=\"description\" content=\"ChocoPoC malware targets researchers through trojanized GitHub PoCs. Learn endpoint, XDR and supply-chain security lessons.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ChocoPoC Malware: Trojanized GitHub Exploits Target Security Researchers\" \/>\n<meta property=\"og:description\" content=\"ChocoPoC malware targets researchers through trojanized GitHub PoCs. Learn endpoint, XDR and supply-chain security lessons.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-19T14:55:47+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T14:56:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ChocoPoC-malware.webp?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"535\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"ChocoPoC Malware: Trojanized GitHub Exploits Target Security Researchers\",\"datePublished\":\"2026-08-19T14:55:47+00:00\",\"dateModified\":\"2026-08-19T14:56:14+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/\"},\"wordCount\":633,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ChocoPoC-malware.webp?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/\",\"name\":\"ChocoPoC Malware: Trojanized GitHub Exploits Target Security Researchers\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ChocoPoC-malware.webp?format=webp\",\"datePublished\":\"2026-08-19T14:55:47+00:00\",\"dateModified\":\"2026-08-19T14:56:14+00:00\",\"description\":\"ChocoPoC malware targets researchers through trojanized GitHub PoCs. Learn endpoint, XDR and supply-chain security lessons.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ChocoPoC-malware.webp?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/ChocoPoC-malware.webp?format=webp\",\"width\":1024,\"height\":535,\"caption\":\"ChocoPoC-malware\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chocopoc-malware-trojanized-poc-exploits\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ChocoPoC Malware: Trojanized GitHub Exploits Target Security Researchers\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ChocoPoC Malware: Trojanized GitHub Exploits Target Security Researchers","description":"ChocoPoC malware targets researchers through trojanized GitHub PoCs. Learn endpoint, XDR and supply-chain security lessons.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/","og_locale":"en_US","og_type":"article","og_title":"ChocoPoC Malware: Trojanized GitHub Exploits Target Security Researchers","og_description":"ChocoPoC malware targets researchers through trojanized GitHub PoCs. Learn endpoint, XDR and supply-chain security lessons.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-19T14:55:47+00:00","article_modified_time":"2026-08-19T14:56:14+00:00","og_image":[{"width":1024,"height":535,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ChocoPoC-malware.webp?format=webp","type":"image\/webp"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"ChocoPoC Malware: Trojanized GitHub Exploits Target Security Researchers","datePublished":"2026-08-19T14:55:47+00:00","dateModified":"2026-08-19T14:56:14+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/"},"wordCount":633,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ChocoPoC-malware.webp?format=webp","articleSection":["Identity Abuse","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/","url":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/","name":"ChocoPoC Malware: Trojanized GitHub Exploits Target Security Researchers","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ChocoPoC-malware.webp?format=webp","datePublished":"2026-08-19T14:55:47+00:00","dateModified":"2026-08-19T14:56:14+00:00","description":"ChocoPoC malware targets researchers through trojanized GitHub PoCs. Learn endpoint, XDR and supply-chain security lessons.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ChocoPoC-malware.webp?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/ChocoPoC-malware.webp?format=webp","width":1024,"height":535,"caption":"ChocoPoC-malware"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/chocopoc-malware-trojanized-poc-exploits\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"ChocoPoC Malware: Trojanized GitHub Exploits Target Security Researchers"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1139","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1139"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1139\/revisions"}],"predecessor-version":[{"id":1143,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1139\/revisions\/1143"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1140"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1139"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1139"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}