TanStack npm Supply Chain Compromise - Correlated Triage: 2+ Indicators

This rule detects potential malicious activity related to the 'gh-token-monitor' toolkit by aggregating suspicious signals across file, process, and network data sources on an individual host. It looks for the presence of specific configuration files or scripts, execution of commands associated with the toolkit or setup processes, and network connections to known command-and-control domains or IP addresses. A host is flagged if it exhibits two or more of these distinct signal categories, suggesting a high-confidence indicator of compromise.