Phishing Page Contacting EvilTokens Device Code API on workers.dev

This rule detects network connections to phishing pages hosted on the workers.dev domain that are attempting to interact with EvilTokens device code API endpoints. These pages are known to implement developer hotkey prevention (F12 blocked, context menu disabled) to hinder in-browser analysis, indicating malicious intent.