LeakySensey: Suspicious private NPM install of patched Claude Code binary

This rule detects the use of 'npm' or 'node' to install packages from a registry other than trusted, standard registries (e.g., npmjs.org, GitHub). It specifically monitors command lines involving 'claude-code' that utilize custom, non-standard registry URLs. This behavior is indicative of potential supply chain attacks or the installation of unauthorized/malicious dependencies.