VS Code node.exe process tree spawns calc.exe (arbitrary payload execution)
Detects a process tree where Code.exe (VS Code) spawns node.exe as an intermediary process, which in turn spawns calc.exe. This matches the child_process.exec execution pattern observed when a malicious VS Code extension dependency decodes and runs an arbitrary command, demonstrating that any payload (not just calc.exe) can be executed via this chain.
Microsoft Sentinel (KQL)

