CVE-2026-33017 Langflow Cryptominer Dropper lambsys/xlamb Persistence

Detects the creation of files with suspicious names (e.g., .xlamb, lambsys) in the /var/tmp directory, initiated by common command-line interpreters or network transfer utilities. This behavior is often indicative of malware deployment or staging in a Linux environment.