npm RAT Chrome Credential Theft via Login Data Access or Dump Files

This rule monitors for unauthorized access to the Google Chrome 'Login Data' database file by processes other than standard browser executables. It also detects the creation of known file artifacts associated with credential-stealing malware or RATs (e.g., 'chrome_logins_dump.txt' or 'gather.tar.gz'), which are indicative of credential harvesting activities.