Linux file creation via curl to /tmp/ld.py (Axios NPM compromise indicators)

Alerts on Linux file creation of /tmp/ld.py by a /curl process, consistent with automated payload staging.

FreeReviewedSigma · High · v5
Product
linux
Category
file_event
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2026-04-01
Updated
2026-07-31

ATT&CK techniques

Initial Access → C2
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule flags Linux file creation activity where the process image ends with '/curl' and the created file is '/tmp/ld.py'. Attackers may use curl to retrieve and stage malicious payloads during supply-chain or initial access workflows. The detection relies on file event telemetry containing the process image path and the target filename being created.

Related detections9 linkedT1105 — drag to rearrange
Suspicious Network Download Spawned by Node.js During Package Install
Linux process chain for Axios NPM compromise: curl download with nohup and python3
macOS: Axios NPM compromise file creation via curl and node indicators
macOS: Detect Axios malicious npm execution chain using osascript, curl download, and cleanup
Windows Process Tree for Axios npm Supply-Chain RAT Droppers (cscript, curl, PowerShell)
Suspicious Remote Script Transfer via Bitsadmin (via process_creation)
Suspicious PowerShell Download Cradle via ClickFix Fake CAPTCHA (via process_creation)
Suspicious Child Process Spawned by Python Interpreter via Process Creation
Malicious Curl MSI Download to ProgramData via Process Creation
Linux file creation via curl to /tmp/ld.py (Axios NPM compromise indicators)
Pivot detection · T1105 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.