GitHub Actions Runner Memory Dump via Python

Detects a Python process attempting to access the memory of another process via the /proc filesystem. This behavior was observed in the Shai-Hulud SAP CAP supply chain attack, where a Python script dumped the Runner.Worker process memory to extract short-lived, high-value tokens passed between CI workflow steps.