Suspicious Node.js Child Process with IPv4 Address

Rule Info

Name
Suspicious Node.js Child Process with IPv4 Address
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects a Node.js child process command line containing an IPv4 address. This might indicate a malicious npm postinstall script downloading second-stage payloads or establishing reverse shells, as observed in various malicious npm campaigns or supply chain attacks.
Date
2026-08-07 00:00:00
Modified
None
Id
82ff3c94-4207-455c-b378-2fc6d01eabc2
Tags
attack.execution attack.t1059.004 attack.command-and-control attack.t1571
Type
Nextron Sigma feed only (private)

Rule History