LWA-2026-3922 MAL-2026-4606 ↗ confirmed malware

martinez-polygon-clipping-tony@0.8.9

Malicious code in martinez-polygon-clipping-tony (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

martinez-polygon-clipping-tony@0.8.9 is a combosquat of the legitimate martinez-polygon-clipping geometry library, published by a throwaway account impersonating the real author. All versions share an identical malicious postinstall (node scripts/postinstall.js) that contacts a C2 server (172[.]86[.]73[.]132 in earlier versions, 10[.]10[.]6[.]129:8787 in later versions) to download OS/arch-specific agent binaries (agent-linux-amd64, agent-darwin-arm64, windows.exe), writes them to tmp, chmods to 0755, and spawns them with detached:true and stdio:ignore for persistence. Multiple versions show the attacker iterating their C2 infrastructure.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 01:45 PM
analyzed
Jun 10, 2026, 02:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.