TanStack npm Supply Chain Compromise - File IOCs (Payload, Persistence, Dead-Man
This rule detects file-based activity associated with a tool named 'gh-token-monitor', which is likely used for the monitoring or exfiltration of GitHub access tokens from a compromised host. The rule monitors for the creation or presence of specific scripts, configuration files, and directory paths associated with this activity, including files related to a 'claude' configuration.
Microsoft Sentinel (KQL)

