martinez-polygon-clipping-tony@0.8.7
Malicious code in martinez-polygon-clipping-tony (npm)
T1195.002 · Compromise Software Supply ChainT1059.007 · JavaScriptT1105 · Ingress Tool TransferT1071.001 · Web Protocols
Analysis
martinez-polygon-clipping-tony@0.8.7 is a combosquat of the legitimate martinez-polygon-clipping geometry library. Its postinstall script downloads a remote Windows binary from hxxp://172[.]86[.]73[.]132/windows.exe via HTTP GET, writes it to disk as windows.exe, and executes it via 'start windows.exe'. The remote-binary download-and-execute pattern is a classic dropper whose second-stage payload is controlled by the attacker's server.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 01:44 PM
- analyzed
- Jun 10, 2026, 01:45 PM
Related advisories
- martinez-polygon-clipping-tony@0.9.4 same package
- martinez-polygon-clipping-tony@0.9.3 same package
- martinez-polygon-clipping-tony@0.9.2 same package
- martinez-polygon-clipping-tony@0.9.1 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.