TanStack npm Supply Chain Compromise - Network Exfil, C2 & Worm Enumeration
Detects network connections to known suspicious infrastructure, including specific domains associated with Session, catbox.moe, or targeted npm registry and GitHub API queries initiated by common command-line utilities. This behavior often suggests adversary communication, data staging, or potential tool/malware delivery.
Microsoft Sentinel (KQL)

