Skip to content
Trojanized GitHub exploits deliver ChocoPoC malware via malicious Python dependencies

Trojanized GitHub exploits deliver ChocoPoC malware via malicious Python dependencies

Feeds.4Sysops IT News July 2, 2026

Threat actors are targeting security researchers and penetration testers by distributing weaponized proof-of-concept exploits on GitHub. Unlike traditional attacks that embed malware directly into exploit files, this campaign utilizes malicious Python packages hosted on the Python Package Index. When a user clones a repository and installs the listed dependencies, a chain of trojanized packages eventually downloads the ChocoPoC remote access trojan. Source