LWA-2026-3924 MAL-2026-4606 ↗ confirmed malware

martinez-polygon-clipping-tony@0.9.1

Malicious code in martinez-polygon-clipping-tony (npm)

T1059 · Command and Scripting InterpreterT1546.016 · Installer Packages

Analysis

Combosquat of the legitimate martinez-polygon-clipping geometry library, published by a throwaway account impersonating the real author. A malicious postinstall (node scripts/postinstall.js) contacts a C2 server (172[.]86[.]73[.]132 in earlier builds, 10[.]10[.]6[.]129:8787 in later ones) to download OS/arch-specific agent binaries (agent-linux-amd64, agent-darwin-arm64, windows.exe), writes them to a temp path, chmods them to 0755, and spawns them with detached:true/stdio:ignore for background persistence.

analyzed by
Leitwacht
first seen
Jun 10, 2026, 01:46 PM
analyzed
Jun 10, 2026, 02:20 PM

Related advisories

browse all confirmed advisories →

Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.