Anti-forensic self-cleanup of indexed-btree malware artifacts
This rule detects potentially malicious activity involving Node.js modules. It monitors for the deletion of specific 'sharedLoad.min.js' or 'extended' files within 'node_modules' directories, the execution of Node.js processes attempting file deletion operations (like 'unlink' or 'rm') within 'node_modules', and the creation or modification of JavaScript files within 'node_modules' that contain 'btree' references. This activity may indicate an attempt to tamper with application dependencies, inject malicious code, or remove artifacts.
Microsoft Sentinel (KQL)

