Rule Info
Name
NPM Package Install Executed From Suspicious Location
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the execution of "npm install" via node.exe from potentially suspicious directories on Windows systems.
It might indicate a malicious package being installed or executed from a non-standard location.
Attacker might use npm packages to execute malicious code on the victim's machine, potentially
leading to data exfiltration, persistence, or further compromise of the system.
Date
2026-06-08 00:00:00
Modified
None
Id
c3f4a8d2-7b1e-4c9f-b5d6-0a8e7f2b3a1d
Tags
attack.execution attack.t1059.007 attack.initial-access attack.t1195.001
Type
Nextron Sigma feed only (private)
