JavaScript Toolchain Execution Chain Leading to Bun Runtime
Detects execution chains where npm launches Node.js and Node.js subsequently launches Bun. This sequence may indicate malicious package execution, dependency confusion attacks, CI/CD compromise, or supply-chain abuse.
Microsoft Sentinel (KQL)

