npm RAT chost.exe / win-driver-xd7d / loader.py Execution from TEMP
Detects indicators of execution related to a known NPM Remote Access Trojan (RAT), including masquerading via chost.exe, execution from specific temporary directories used by the malware, and Python scripts executing a loader.py file from temporary locations.
SentinelOne

