Malicious Node Runtime Spawning Shell to Download Python Payload via Axios Compromise

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-19
Updated
2026-09-19

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a Node or Bun runtime spawning a shell that uses curl to fetch a Python loader into tmp and launches it with nohup as observed in the Axios npm supply chain compromise. A JavaScript package executing curl and python3 in sequence indicates malicious postinstall behavior staging a backdoor on the developer host.

Related detections9 linkedT1059.004 — drag to rearrange
Linux process chain for Axios NPM compromise: curl download with nohup and python3
macOS: Detect Axios malicious npm execution chain using osascript, curl download, and cleanup
Malicious Remote Script Piped to Shell via Curl (via process_creation)
Suspicious Secret Scanning with trufflehog Verified Results
Possible GTFOBins Shell Breakout via Unix Utilities
Malicious Foomatic-Rip Filter Spawning Shell via CUPS Exploitation
Suspicious Downloaded Shell Stager Made Executable Via Chmod 777
Malicious Shai-Hulud Workflow File Creation
Suspicious Reverse Shell via bash to dev tcp (via process_creation)
Malicious Node Runtime Spawning Shell to Download Python Payload via Axios Compromise
Pivot detection · T1059.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.