Rule Info
Name
Suspicious Node.js Child Process with IP Address - Linux
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects a Node.js process spawning a shell or network utility with a command line containing an IPv4 address.
This pattern is commonly used by malicious npm postinstall scripts to download second-stage payloads or establish reverse shells, as observed in various malicious Strapi npm campaign.
Date
2026-08-07 00:00:00
Modified
None
Id
810641e4-c84c-4e79-b62f-97ec64c78992
Tags
attack.execution attack.t1059.004 attack.command-and-control attack.t1571
Type
Nextron Sigma feed only (private)
