AMOS Shell Credential Harvesting Spawned from AI Agent Runtime Process

This rule detects shell commands (bash, sh, zsh) initiated by AI-agent or development-related processes (e.g., Python, Claude Desktop, openclaw) that target sensitive macOS paths associated with credentials, SSH keys, crypto wallets, and browser cookies, a technique characteristic of the Atomic Stealer (AMOS) malware.