martinez-polygon-clipping-tony@0.9.2
Malicious code in martinez-polygon-clipping-tony (npm)
T1071.001 · Web Protocols
Analysis
Combosquat of the legitimate martinez-polygon-clipping geometry library, published by a throwaway account impersonating the real author. A malicious postinstall (node scripts/postinstall.js) contacts a C2 server (172[.]86[.]73[.]132 in earlier builds, 10[.]10[.]6[.]129:8787 in later ones) to download OS/arch-specific agent binaries (agent-linux-amd64, agent-darwin-arm64, windows.exe), writes them to a temp path, chmods them to 0755, and spawns them with detached:true/stdio:ignore for background persistence.
- analyzed by
- Leitwacht
- first seen
- Jun 10, 2026, 01:47 PM
- analyzed
- Jun 10, 2026, 02:20 PM
Related advisories
- martinez-polygon-clipping-tony@0.9.4 same package
- martinez-polygon-clipping-tony@0.9.3 same package
- martinez-polygon-clipping-tony@0.9.1 same package
- martinez-polygon-clipping-tony@0.9.0 same package
- martinez-polygon-clipping-tony@0.8.9 same package
- maninos@1.2.0
- cache-section-helper@1.0.7
- lucifer490-v2@1.1.65
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.