martinez-polygon-clipping-tony@0.8.9
Malicious code in martinez-polygon-clipping-tony (npm)
Analysis
martinez-polygon-clipping-tony@0.8.9 is a combosquat of the legitimate martinez-polygon-clipping geometry library, published by a throwaway account impersonating the real author. All versions share an identical malicious postinstall (node scripts/postinstall.js) that contacts a C2 server (172[.]86[.]73[.]132 in earlier versions, 10[.]10[.]6[.]129:8787 in later versions) to download OS/arch-specific agent binaries (agent-linux-amd64, agent-darwin-arm64, windows.exe), writes them to tmp, chmods to 0755, and spawns them with detached:true and stdio:ignore for persistence. Multiple versions show the attacker iterating their C2 infrastructure.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 01:45 PM
- analyzed
- Jun 10, 2026, 02:20 PM
Related advisories
- martinez-polygon-clipping-tony@0.9.4 same package
- martinez-polygon-clipping-tony@0.9.3 same package
- martinez-polygon-clipping-tony@0.9.2 same package
- martinez-polygon-clipping-tony@0.9.1 same package
- maninos@1.2.0
- cache-section-helper@1.0.7
- lucifer490-v2@1.1.65
- prettier_v1@3.8.4
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.