Compromised Node.js Package Shell Execution T1195.002 T1059.001
Detects instances where the Node.js executable (node.exe) spawns common command shells or scripting interpreters such as cmd.exe, powershell.exe, pwsh.exe, or wscript.exe. This behavior is often indicative of Node.js-based applications being used as a staging point for command execution, a common pattern in post-exploitation or the usage of malicious npm packages.
Splunk (SPL)

