Malicious Node.js Process Spawning Unix Shell or Network Client

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a Node.js server process spawning a Unix shell, curl, or wget, a strong indicator of remote code execution against a web application. This behavior was central to CVE-2025-55182 React2Shell exploitation of React Server Components where the crafted Next-Action request drove child_process execution. Web application runtimes should not normally launch interactive shells or downloaders, so this lineage signals hands-on-keyboard post-exploitation.

Related detections9 linkedT1059.004 — drag to rearrange
Suspicious Shell Spawned by ActiveMQ Java Process
Possible Bitbucket Pre-Auth RCE via git archive exec Null-Byte Injection (CVE-2022-36804) (via webserver)
Malicious PostgreSQL COPY FROM PROGRAM Command Execution via Managed Cloud Database (via process_creation)
Suspicious PAN-OS Shell Execution Setting panusername via Command Injection (via process_creation)
Malicious OMI Server Spawning Shell as Root via OMIGOD SCX Provider (via process_creation)
Possible F5 iControl REST Remote Code Execution via Util Bash Endpoint
Cleo File Transfer Software Spawning Command Interpreter
Suspicious Exfiltration of Environment File via wget POST
Malicious Encrypted Reverse Shell via Netcat and GPG on Linux
Malicious Node.js Process Spawning Unix Shell or Network Client
Pivot detection · T1059.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.