npm install of malicious indexed-btree family packages

This rule monitors for the installation of specific known-malicious or suspicious NPM packages that are commonly used in supply chain attacks. It identifies the execution of npm (or node) commands to install or add packages explicitly listed as malicious by security research, which may indicate a supply chain compromise or an attempt to introduce unauthorized code into the development environment.