npm RAT Dropper: PowerShell ZIP Download and VBS Execution via winPatch

Detects a sequence of events where PowerShell is used to download files from 'nvidiadriver.net' or with filenames containing 'winPatch', followed by a suspicious file drop (specifically 'winPatch.zip' or 'update.vbs') in a temporary directory within a 30-minute window. This behavior is indicative of potential initial staging for a RAT or malicious script deployment.