martinez-polygon-clipping-tony@0.9.0
Malicious code in martinez-polygon-clipping-tony (npm)
Analysis
martinez-polygon-clipping-tony@0.9.0 is a combosquat of the legitimate martinez-polygon-clipping geometry library, published by a throwaway account impersonating the real author. All versions share an identical malicious postinstall (node scripts/postinstall.js) that contacts a C2 server (172[.]86[.]73[.]132 in earlier versions, 10[.]10[.]6[.]129:8787 in later versions) to download OS/arch-specific agent binaries (agent-linux-amd64, agent-darwin-arm64, windows.exe), writes them to tmp, chmods to 0755, and spawns them with detached:true and stdio:ignore for persistence. Multiple versions show the attacker iterating their C2 infrastructure.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 01:46 PM
- analyzed
- Jun 10, 2026, 02:20 PM
Related advisories
- martinez-polygon-clipping-tony@0.9.4 same package
- martinez-polygon-clipping-tony@0.9.3 same package
- martinez-polygon-clipping-tony@0.9.2 same package
- martinez-polygon-clipping-tony@0.9.1 same package
- @klapp-sca/routes@99.0.1
- @klapp-login-platform/routes@99.0.2
- ai-sdk-helpers@1.2.0
- ai-sdk-helpers@1.4.2
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.