Miasma npm Malware - node-gyp binding.gyp Code Execution

This rule detects potentially malicious activity related to the 'node-gyp' build tool used by npm. It monitors for two patterns: 1) npm spawning node-gyp, which can be an automated trigger for malicious binding.gyp files, and 2) node-gyp spawning node.exe with command-line arguments indicative of obfuscated JavaScript (e.g., base64 encoding, eval, AES-GCM patterns), a technique often seen in malicious Node.js packages.