Suspicious Bun Runtime Spawned by Node During npm Lifecycle

PremiumReviewedSigma · Medium · v1
Category
process_creation
Author
HuntRule
Published
2026-10-05
Updated
2026-10-05

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the Node.js process launching the Bun JavaScript runtime, a chain observed when malicious npm packages execute payloads through Bun during install or lifecycle events. It is associated with software supply chain attacks that weaponize trusted developer workflows to run code on build and developer hosts. Detecting this uncommon parent-child pair surfaces post-install package execution abuse.

Related detections9 linkedT1059.001 — drag to rearrange
Suspicious Node Package Install Spawning Script Interpreters via process_creation
Suspicious Node.js Spawning Script Interpreter for Dropped Payload
Malicious PowerShell Download from bullethost.cloud Staging Server
Suspicious Node.js Spawning PowerShell Archive Download to Temp
Suspicious PowerShell Remote File Download Cmdlets (via ps_script)
Malicious Office Application Spawning Command Interpreter
Suspicious PowerShell Encoded Command Execution
Suspicious Office Application Spawning Script Interpreter
Suspicious Microsoft Word Spawning PowerShell
Suspicious Bun Runtime Spawned by Node During npm Lifecycle
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.