Miasma npm Supply Chain - Bun Runtime Downloaded and Executed Post npm Package Install

This rule detects suspicious activity associated with the Bun runtime after an npm package install. It flags instances where Bun, or download utilities (curl/wget) fetching 'bun.sh', are spawned from Node.js-related processes (npm, node, node-gyp) particularly when located in common temporary or cache directories, indicating potential supply chain compromise or unauthorized runtime deployment during build processes.