Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
GitHub has become the latest delivery mechanism for malware aimed at security researchers. . YesWeHack and Sekoia identified a campaign that hid a Python-based remote access trojan (RAT) called ChocoPoC inside repositories presented as proof-of-concept exploits for recently disclosed vulnerabilities. Someone looking for a working exploit could clone the project, execute the code, and unknowingly launch a second payload that established remote access. Nothing about the campaign specifically targets Linux. The workflow does. Linux remains a common platform for exploit development, reverse engineering, malware analysis, and penetration testing, so it's also a common place to download and test public PoCs. That makes research workstations an appealing target when attackers decide the easiest way to reach an organization is through the people analyzing its vulnerabilities. How Trojanized GitHub PoC Repositories Delivered ChocoPoC Malware The campaign centers on the deployment of trojanized repositories that mimic legitimate exploit research. When a researcher clones and executes the code to validate a vulnerability, the malicious payload executes alongside the advertised exploit. Once the malicious script is triggered, it can establish remote access, allowing attackers to execute commands remotely on the compromised system. The repositories were designed to resemble legitimate security research projects, allowing the embedded malicious code to blend into routine research workflows. The Campaign Highlights a Common Workflow Risk The campaign highlights a standard practice among vulnerability researchers: downloading public proof-of-concept code to validate newly disclosed vulnerabilities. Linux is widely used for these tasks because of its native development tools, scripting ecosystem, and established penetration-testing distributions. Because researchers frequently execute public exploit code during vulnerability validation, Linux research environments can become attractive targets forcampaigns that abuse trusted repositories. Trust Abuse in Open Source Research Workflows ChocoPoC isn't remarkable because of the malware itself. Security researchers have seen Python backdoors before. What stands out is where it was hidden. Public proof-of-concept repositories have become a routine part of vulnerability research, and attackers are now using that expectation against the people who depend on them. This incident is part of a wider pattern of trust abuse on public code-sharing platforms. Academic research presented at USENIX WOOT 2025 in the paper SecurePoC: A Helping Hand to Identify Malicious CVE Proof of Concept Exploits in GitHub demonstrates that malicious and misleading proof-of-concept repositories have become a significant enough problem to warrant dedicated detection research ( USENIX WOOT 2025, el-Yadmani et al. ; Zenodo Artifact ). The researchers identified numerous cloned and modified repositories containing malicious additions, highlighting how public code-sharing platforms have become an attractive distribution channel for malicious proof-of-concept repositories. Why Linux Users Should Pay Attention ChocoPoC is not a Linux-specific threat. The malicious repositories described by YesWeHack and Sekoia could affect researchers working on Windows, macOS, or Linux. What makes the campaign relevant to Linux users is how many security professionals perform vulnerability research. Linux is widely used for penetration testing, exploit development, reverse engineering, and malware analysis. As a result, Linux workstations, virtual machines, and lab environments are common places to clone and execute public proof-of-concept code. The campaign exploits that research workflow, not the operating system itself. For Linux users who regularly test exploits from public repositories, it serves as a reminder that the repository deserves the same level of scrutiny as the vulnerability being investigated. Reducing Risk When Testing Public Exploit Code As public exploitrepositories become a more frequent source of opportunistic attacks, the security of the researcher’s workstation must be prioritized. Researchers should begin by performing a thorough source inspection, reviewing PoC code for obfuscated commands, unexpected network calls, or hardcoded IPs before any execution. Beyond manual review, consider using disposable virtual machines or isolated container environments when validating exploit code to ensure that malicious payloads cannot reach your host filesystem or network. For those working in Windows-based environments, Microsoft has recently launched a public preview of WSL Containers (WSLC), which allows for the creation of native, isolated Linux container environments ( Microsoft Dev Blog ; Microsoft Learn ; WSL API Reference ; Phoronix ). Furthermore, researchers should perform due diligence by assessing repository reputation, commit history, and the author's track record rather than relying on the code’s presence alone. Finally, monitoring outbound network connections during the testing phase is a practical way to identify and block any unexpected traffic generated by a script. Conclusion ChocoPoC serves as a critical reminder that the security industry’s own workflows are now firmly in the crosshairs of threat actors. As public exploit repositories continue to grow in volume, the ability to validate the integrity of the code we download is becoming just as essential as the ability to validate the vulnerabilities the code aims to address. Security professionals must treat unverified PoC code with the same scrutiny as any other untrusted software. . ChocoPoC malware highlights a serious risk in GitHub PoC repositories, impacting security researchers across platforms.. malware delivery techniques, security researcher risks, public code repositories, ChocoPoC attacks. . MaK Ulac
Security researchers have discovered a Linux-based remote access trojan (RAT) that uses an unusual stealth technique to remain out of sight from security products. The malware, dubbed CronRat, hides in the calendar subsystem of Linux servers (“cron”) on a non-existent day, 31 February, according to a blog post by security researchers at Sansec. . The researchers said that CronRat “enables server-side Magecart data theft which bypasses browser-based security solutions”. The malware was discovered on several eCommerce websites injecting Magecart payment skimmers in server-side code. . Explore the methods employed by the Trickster spyware, which utilizes evasion tactics for data breaches in various online retail platforms, affecting countless digital commerce websites.. CronRat, Linux Malware, Remote Access Trojan, Magecart Exploit, Data Theft Techniques. . LinuxSecurity.com Team
A newly discovered Windows trojan linked to the AridViper threat group, dubbed PyMICROPSIA, shows signs that it might be used to infect computers running Linux and macOS as well. . The new trojan, dubbed PyMICROPSIA by Unit 42, was discovered while investigating AridViper activity (also tracked as Desert Falcon and APT-C-23), a group of Arabic speaking cyberspies focusing their attacks on Middle Eastern targets since at least 2011. AridViper operates mainly out of Palestine, Egypt, and Turkey, and the number of victims they compromised exceeded 3,000 in 2015 [PDF], according to the Global Research and Analysis Team (GReAT) at Kaspersky Lab. . The latest malware strain, named AquaSPIKE by ThreatIntel Team, emerged during a probe into the operations of SolarTide, which aimed at various cloud platforms.. PyMICROPSIA Trojan, Linux Threat, macOS Malware, Cybersecurity Alerts. . LinuxSecurity.com Team
The eight-year-old Stantinko botnet has updated its Linux malware - now posing as an Apache web server. . Stantinko, one of the oldest malware botnets still operating today, has rolled out updates to its class of Linux malware, upgrading its trojan to pose as the legitimate Apache web server process (httpd) in order to make detection harder on infected hosts. The upgrades, spotted by security firm Intezer Labs , come to confirm that despite a period of inactivity in regards to code changes, the Stantinko botnet continues to operate even today. . Puppetmaster, among the most enduring cyber threat networks currently active, has introduced enhancements to its series of Linux-based malicious software.. Linux Malware, Botnet Threats, Apache Web Server Attack, Stantinko Update. . LinuxSecurity.com Team
Threat actors are leveraging a botnet made up of infected Linux machines to launch powerful distributed denial-of-service (DDoS) attacks against as many as 20 targets per day, according to Akamai's Security Intelligence Response Team (SIRT). . The botnet is composed of Linux machines infected with a stealthy trojan identified in 2014 as "XOR DDoS." The threat was observed altering its installation depending on the victim's Linux environment and running a rootkit to avoid detection. . The botnet is composed of Linux machines infected with a stealthy trojan identified in 2014 as 'XOR . threat, actors, leveraging, botnet, infected, linux, machines, launch, powerful, distribu. . Alex
Out of band authentication . But RSA's Anti-Fraud Command Center on Monday found and reported on a Trojan called Bugat that has been updated to hijack out-of-band authentication codes sent to bank customers via SMS. This doesn't mean out-of-band authentication via text messaging is useless, but it can be compromised using a dated, unsophisticated piece of malware. The link for this article located at American Banker is no longer available. . The Cybersecurity Agency warns of the Zett Malware intercepting mobile transaction confirmations, underlining the potential threat.. Bugat Trojan, SMS Authentication, Banking Malware, Trojan Risks, Out-of-Band Authentication. . LinuxSecurity.com Team
An outbreak of a worm on Tumblr, the microblogging platform, hit many accounts by taking advantage of the platform's reblogging capability. The payload of the worm was the publication of a posting angrily explaining how the worm's authors hated Tumblr users, was analysed by Sophos which noted that the malicious code was embedded mostly as a Base64-encoded string hidden within a data URI. . Once decoded and executed, it would pull code and content from another website. The link for this article located at H Security is no longer available. . Instagram profiles targeted by malware exploiting share function; contents uncovered as Base64-encoded virus for harmful activities.. Tumblr Worm Attack, Malicious Payload, Trojan Code, Microblogging Security. . LinuxSecurity.com Team
A 20-year-old British man will spend the next 18 months behind bars for stealing "Call of Duty" gamers' credit card numbers and other confidential data and selling it to other cybercriminals. . Lewys Martin created a Trojan to remotely monitor gamers' keystrokes, giving him access to their bank and credit card numbers, passwords and PayPal accounts, Kent Online reported. The link for this article located at MSNBC is no longer available. . Lewys Martin created a Trojan to remotely monitor gamers' keystrokes, giving him access to their ban. 20-year-old, british, spend, months, behind, stealing, 'call, duty'. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.