Install of known hallucinated/slopsquatted package via pip/npm
This rule detects the use of package managers like 'pip' or 'npm' to install specific suspicious software packages or tools often associated with supply chain compromise or malicious library installation (e.g., 'huggingface-cli', 'unused-imports', 'react-codeshift').
Microsoft Sentinel (KQL)

