Package post-install script accessing credential files or cloud creds

Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.