Rule Info
Name
Node or Bun Execution from Suspicious Locations - Linux
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the execution of build tools such as bun and node from potentially suspicious locations on Linux systems.
In the recent trend of npm supply chain attacks, Threat Actors have been observed to execute
build tools such as bun and node from locations that are not commonly used for legitimate purposes.
Date
2026-06-08 00:00:00
Modified
None
Id
dad274c1-8f8a-42fe-8d8d-55abd962e7ae
Tags
attack.execution attack.t1059.007
Type
Nextron Sigma feed only (private)
