Node.exe spawns interactive CMD/PowerShell child process (ConPTY RAT)

Detects instances where the Node.js runtime process (node.exe) spawns a command shell (cmd.exe) or PowerShell (powershell.exe). This pattern is frequently used by malicious Node.js-based applications, RATs, or web shells to execute arbitrary commands on a compromised host.