Suspicious LOLBin Execution from npm/pip Postinstall Scripts

Detects the execution of command-line tools (powershell, cmd, bash, curl, etc.) originating from common package managers and build tools (npm, node, pip, python, yarn). The rule flags these processes if they contain command-line arguments indicative of suspicious activity such as base64-encoded commands, remote script execution (IEX, curl/wget to shell), or indicators of persistence mechanisms (scheduled tasks, registry Run keys).