Unsigned PAM module implanted in su/sudo auth stack with non-package-manager pam.d tampering

Detects an unsigned/unexpected PAM module written into the su/sudo authentication stack, correlated with non-package-manager modification of /etc/pam.d/ configuration and subsequent su/sudo activity — the technique Jewelbug's Linux tooling uses to steal credentials.