PoC Repos Become the Malware Trap

The danger is not the target product. It is the habit of running public proof-of-concept code as if the repository were safe, because that trust boundary is what gets crossed here. A researcher testing a PoC can end up executing the attacker’s payload instead of the exploit sample they thought they were validating. Multiple trojanized GitHub PoC repos were found delivering ChocoPoC, a Python RAT that can run commands and steal sensitive data. The campaign is believed to target cybersecurity researchers, especially teams that download and execute public exploit demos or research code in lab environments. That shifts the risk from the vulnerable software to the validation workflow itself. If the lab is connected or loosely isolated, the sample can turn analysis work into command execution and data loss.

Part of the PlainSec briefing for 2026-07-03

Sources