MCP-style package install spawning credential access or network exfil
Detects instances where package management tools (pip, npm, docker) spawn child processes that immediately attempt to read sensitive files (SSH keys, cloud/container credentials) or perform outbound network connections. This behavior is indicative of a trojanized supply-chain package executing malicious post-install logic to exfiltrate secrets or establish initial communication with a C2 server.
Sigma

