WeaselBiscuit Malicious npm package install (13-package cluster)
This rule detects the execution of npm or node.js commands involving specific, potentially malicious package names or internal project naming patterns often associated with dependency confusion or supply chain attacks. It monitors npm/node CLI arguments for targeted library names or installation commands that deviate from standard organizational behavior.
Microsoft Sentinel (KQL)

