Windows Execution of tanstack_runner.js via bun.exe

Flags bun.exe launching a script via "run tanstack_runner.js" on Windows.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Leonardo Gasparini (SigmaHQ), DRL 1.1
Published
2026-05-12
Updated
2026-07-31

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

Identifies Windows process creation where the executed image ends with bun.exe and the command line includes both 'run' and 'tanstack_runner.js'. This can indicate automated execution of a JavaScript runner tied to a supply-chain-style compromise attempt targeting npm packages. The rule relies on process creation telemetry with executable path/filename and full command-line content.

Related detections9 linkedT1059.007 — drag to rearrange
SocGholish Fake Browser Update Script Execution (via process_creation)
Suspicious Script Host Execution of JavaScript From a User-Writable Directory (via process_creation)
Linux process execution indicators for TanStack preinstall supply-chain payloads
Windows AppLocker Audit-Mode Events Indicate Files Would Have Been Blocked
Windows AppLocker Blocked Application, Script, MSI, or Packaged-App Execution
Suspicious n8n Campaign RMM Installer Masquerading as OneDrive Document
Suspicious npm Postinstall Node Execution From Fixtures Path (BeaverTail OtterCookie)
Suspicious Script Host Execution of Decoy-Named JavaScript Dropper (PS1Bot)
Malicious Emmenhtal JavaScript Loader Spawning Encoded PowerShell
Windows Execution of tanstack_runner.js via bun.exe
Pivot detection · T1059.007 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.