New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

Attackers are hiding a data-stealing trojan inside fake exploit code aimed at the people who hunt bugs for a living. The malware, called ChocoPoC, travels in Python proof-of-concept (PoC) repositories on GitHub that claim to exploit hot new CVEs.

Run one, and it quietly lifts your saved passwords, browser cookies, and files, then hands the attacker a shell on your machine. YesWeHack and

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Demis Hassabis has a plan to harness AI safely

Demis Hassabis has a plan to harness AI safely Source: Hacker News

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or

CEO of Mistral: AI is software. It can be controlled

CEO of Mistral: AI is software. It can be controlled Source: Hacker News