Sapphire Sleet npm Supply Chain - node/npm Spawning Shell or curl (T1195.001)

Detects instances where Node.js (node.exe) or the Node Package Manager (npm.exe) process initiates common command-line shells (cmd.exe, powershell.exe) or network utility tools (curl.exe). This behavior is often associated with software supply chain attacks, exploitation of web applications, or malicious post-exploitation activity where Node-based environments are leveraged to execute system commands or download external payloads.