Suspicious Node.js Spawning Script Interpreter for Dropped Payload

PremiumReviewedSigma · Medium · v1
Category
process_creation
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects a Node.js process launching the Windows script host or a Python interpreter against a payload staged in the temp directory, the dropper chain of the compromised axios package RAT. The malicious postinstall script writes a VBS or Python loader to a temp location and executes it to establish the cross-platform RAT. Node spawning wscript or python on a temp script is anomalous for normal package installs.

Related detections9 linkedT1059.001 — drag to rearrange
Malicious PowerShell Download from bullethost.cloud Staging Server
Suspicious Node.js Spawning PowerShell Archive Download to Temp
Malicious Node.js Execution of Hidden .claude Setup Script
Suspicious PowerShell Remote Download and Execution via Invoke-WebRequest
Malicious axios NPM Supply Chain C2 Domain Resolution
Suspicious Script Host Spawning Hidden PowerShell (via process_creation)
Suspicious PowerShell Reflective Assembly Load With GZip Decompression (via process_creation)
Suspicious PowerShell Invoke-Expression with Replace Obfuscation
Suspicious PowerShell Archive Extraction to AppData Roaming
Suspicious Node.js Spawning Script Interpreter for Dropped Payload
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.