A new data-stealing trojan, ChocoPoC, has been discovered as a Remote Access Trojan (RAT) that propogates through Proof of Concept (PoC) repositories. The trojan remains hidden in a repository's dependencies, making it immune to scans of just the PoC. In addition, it only activates after the repo is fully cloned and a specific file is executed, making detection very difficult until the trojan actually turns on. From there, the trojan gains administrator access to passwords, cookies, and files on whatever browser the victim uses, such as Chrome, Edge, Firefox, and Brave. In addition, the trojan hides in plain sight, executing orders from a Mapbox API and deploying domain-fronting to mask its IP.