Suspicious install of trojanized MCP/AI-tooling package + outbound connection
Detects the installation of AI-related packages (e.g., mcp, tiktoken_mcp) via common package managers (pip, npm, docker) followed by an outbound network connection from the same host within 10 minutes. This behavior is consistent with supply chain attacks where trojanized AI/MCP components are used to initiate command-and-control communication shortly after deployment.
Microsoft Sentinel (KQL)

