Suspicious Execution From Hidden fonts-unix Directory in tmp on Linux

PremiumReviewedSigma · High · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-10-09
Updated
2026-10-09

ATT&CK techniques

Initial Access → C2
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. Exfiltration

  12. Impact

What it detects

This rule detects process execution from the hidden /tmp/.fonts-unix directory on Linux. The AdaptixC2 agent delivered through a malicious npm supply-chain package staged its Linux payload in this location to blend in with legitimate font-socket directories. Executing a binary from a world-writable hidden temp path is a strong indicator of malware staging and persistence on Unix hosts.

Related detections9 linkedT1105 — drag to rearrange
Malicious axios NPM Supply Chain C2 Domain Resolution
Suspicious Network Download Spawned by Node.js During Package Install
Linux process chain for Axios NPM compromise: curl download with nohup and python3
macOS: Axios NPM compromise file creation via curl and node indicators
macOS: Detect Axios malicious npm execution chain using osascript, curl download, and cleanup
Linux file creation via curl to /tmp/ld.py (Axios NPM compromise indicators)
Windows Process Tree for Axios npm Supply-Chain RAT Droppers (cscript, curl, PowerShell)
Suspicious Process Execution From Windows Tasks Directory
Suspicious Malicious MCP Package devtools-assistant Execution (via process_creation)
Suspicious Execution From Hidden fonts-unix Directory in tmp on Linux
Pivot detection · T1105 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.