Backdoor Web Shell Access (OptinMonster Campaign)
Detects interaction with specific web shell or remote code execution parameters ('developer_api1_fm', 'developer_api1_eval') associated with the self-hiding backdoor plugin dropped during the OptinMonster supply chain attack. This rule identifies HTTP requests containing these parameters, which are highly specific to the threat actor involved in the OptinMonster supply chain compromise.
Microsoft Sentinel (KQL)

