npm

martinez-polygon-clipping-tony

martinez-polygon-clipping-tony is identified in the SafeDep analysis "martinez-polygon-clipping-tony: Trojanized npm Fork Drops Telegram RAT". martinez-polygon-clipping-tony is a trojanized fork of the legitimate martinez-polygon-clipping npm package. The postinstall hook downloads a PyInstaller-packed Telegram bot from 172.86.73.132 that provides full remote shell, screenshot capture, file upload/download, and self-destruct capabilities on Windows targets.

discovered 2026-05-07

Threat types

ratpersistence

Malicious versions

  • 1.0.0

Campaigns

Indicators

Techniques

Read the full analysis →