LWA-2026-3921 MAL-2026-4606 ↗ confirmed malware

martinez-polygon-clipping-tony@0.8.7

Malicious code in martinez-polygon-clipping-tony (npm)

T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols

Analysis

martinez-polygon-clipping-tony@0.8.7 is a combosquat of the legitimate martinez-polygon-clipping geometry library. Its postinstall script downloads a remote Windows binary from hxxp://172[.]86[.]73[.]132/windows.exe via HTTP GET, writes it to disk as windows.exe, and executes it via 'start windows.exe'. The remote-binary download-and-execute pattern is a classic dropper whose second-stage payload is controlled by the attacker's server.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 01:44 PM
analyzed
Jun 10, 2026, 01:45 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.