npm binding.gyp Silent Node Execution (Miasma Campaign)

Detects process execution indicative of the npm binding.gyp GYP shell expansion exploit used in the Miasma campaign to silently run node. This rule specifically looks for Node.js process executions with a command line matching a unique regex pattern associated with the exploit: 'node index.js > /dev/null 2>&1 && echo stub.c'.