Node.js binary staged under masquerading Windows profile subpaths

Detects the presence of Node.js runtime files (node.exe, index.js) or script-based agents (vbs, ps1) located within user-profile paths (AppData) that mimic legitimate Windows system folders. This pattern is characteristic of masquerading techniques used to stage or run malicious agents under the guise of system components.