malware
npm
martinez-polygon-clipping-tony
discovered 2026-05-07martinez-polygon-clipping-tony is identified in the SafeDep analysis "martinez-polygon-clipping-tony: Trojanized npm Fork Drops Telegram RAT". martinez-polygon-clipping-tony is a trojanized fork of the legitimate martinez-polygon-clipping npm package. The postinstall hook downloads a PyInstaller-packed Telegram bot from 172.86.73.132 that provides full remote shell, screenshot capture, file upload/download, and self-destruct capabilities on Windows targets.
Threat types
rat persistence
Malicious versions
- 1.0.0