Spearphishing Campaign Abuses npm Registry

This rule detects network connections or URL click events to a list of domains known to be associated with phishing or malware distribution. The rule specifically looks for connections to these domains that also contain certain path segments like '/wlc/', '/load/', or '/success/', which are often indicative of malicious activity or payload delivery. It also broadly checks for any URL click events containing these suspicious domains.