Affected Systems

Vulnerability researchers and security professionals using GitHub to access proof-of-concept exploit code. The ChocoPoC malware targets Windows systems, stealing credentials, browser data, and files while establishing remote shell access.

Exploitation Status

Active campaign confirmed. Attackers are actively distributing malicious repositories on GitHub disguised as legitimate vulnerability research and exploit code.

Business Impact

Security and vulnerability research teams are at direct risk. Compromise of researcher workstations could expose internal vulnerability data, credentials for corporate systems, browser sessions, and sensitive files. Remote shell access enables lateral movement and persistent access to research environments. Organizations relying on GitHub for threat intelligence gathering face elevated supply chain risk.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Alert security research and threat intelligence teams about the ChocoPoC campaign and advise extreme caution when downloading PoC code from GitHub
  • Implement mandatory sandboxing or isolated VM environments for all external exploit code testing; prohibit execution on corporate workstations
  • Monitor endpoint detection systems for suspicious PowerShell activity, credential dumping behavior, and unauthorized outbound connections from researcher systems
  • Review recent GitHub repository clones by security staff and scan systems for ChocoPoC indicators of compromise (password stealer modules, browser cookie theft, reverse shell artifacts)
  • Enforce multi-factor authentication on all critical systems to limit damage from stolen credentials; rotate credentials for researchers who may have accessed suspicious repositories