Shai-Hulud npm Supply Chain: node.exe Spawning Shell from npm Path

Detects instances where the Node.js runtime (node.exe) spawns a command shell or scripting interpreter (cmd.exe, powershell.exe, or wscript.exe). The detection specifically looks for these processes being initiated from directories commonly associated with Node.js package management (npm) or local module installations, which may indicate malicious activity such as software supply chain attacks or execution of obfuscated scripts.