Supply Chain Compromise via Malicious npm/pip Package Execution T1195.002

Detects instances where package managers like npm, pip, or python execute shells or scripting interpreters with command-line arguments indicative of software installation or build processes. This pattern is common in supply chain attacks where malicious packages run code during their installation phase.