Suspicious Node Package Install Spawning Script Interpreters via process_creation

PremiumReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-30
Updated
2026-09-30

ATT&CK techniques

Initial Access → Execution
  1. Recon

  2. Resource Dev

  3. Persistence

  4. Priv Esc

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects node.exe spawning cscript, wscript, or powershell child processes. The compromised axios npm package ran a setup.js install script that chained into Windows script hosts and PowerShell to fetch and execute the next stage, so a Node process launching these interpreters indicates a malicious package post-install execution chain.

Related detections9 linkedT1059.001 — drag to rearrange
Suspicious Windows Script Host Spawning PowerShell via Gootloader
Suspicious Node.js Spawning Script Interpreter for Dropped Payload
Malicious Script Host Spawning PowerShell With Invoke-Expression (via process_creation)
Malicious PowerShell Download from bullethost.cloud Staging Server
Suspicious Script Host Spawning PowerShell via BlindEagle Chain
Suspicious Node.js Spawning PowerShell Archive Download to Temp
Suspicious WScript Spawning PowerShell From VBS Loader via wscript.exe (via process_creation)
Suspicious PowerShell Spawned by Windows Script Host from HTML Smuggling (via process_creation)
Suspicious PowerShell Spawned by Windows Script Host via Process Creation (via process_creation)
Suspicious Node Package Install Spawning Script Interpreters via process_creation
Pivot detection · T1059.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.