Gradle Build Spawns sh -c Shell via Malicious preBuild/doLast Hook
Detects instances where a Gradle or Java build process invokes a shell (sh -c) containing suspicious build-related keywords such as 'preBuild', 'doLast', or 'tasks.all'. This pattern is commonly observed in supply chain compromises where malicious code is injected into build scripts to execute hidden payloads during the compilation phase.
Sigma

