sckit BASH_ENV injection into GITHUB_ENV to source malicious bridge script

Detects malicious shell commands attempting to perform supply-chain persistence via environment variable manipulation in CI/CD environments. The rule identifies processes injecting BASH_ENV into GITHUB_ENV, a known technique used by the SCKIT supply-chain worm to perform credential harvesting during CI pipeline execution.