Bun JavaScript Runtime Executed Via Shell Spawned By Node.js On Linux

Rule Info

Name
Bun JavaScript Runtime Executed Via Shell Spawned By Node.js On Linux
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects a Linux shell process (e.g. bash, sh, dash) spawned by Node.js with a command line referencing the Bun runtime, indicating a Node.js -> Shell -> Bun execution chain. This pattern is commonly observed in supply chain attacks where a malicious npm package abuses Node.js to launch a shell that invokes Bun as a second-stage JavaScript or TypeScript payload runner. Bun is attractive to attackers due to its native TypeScript support, fast startup, and broad system APIs, while being less scrutinized by EDR/AV solutions compared to Node.js itself.
Date
2026-05-21 00:00:00
Modified
None
Id
7bf1e37f-311c-4cad-bd2b-eb007216f25a
Tags
attack.execution attack.t1059.007
Type
Nextron Sigma feed only (private)

Rule History