npm publish immediately following workflow tampering (0.2.21 pattern)
Detects instances where a repository's GitHub CI/CD workflow, git configuration, or repository settings are modified, followed shortly thereafter by an npm package publish event. This behavior is indicative of a supply chain compromise where an adversary modifies workflow files to auto-publish malicious versions of a package.
Microsoft Sentinel (KQL)

