heroui logo

Curl Download Activity from npm Package Install

Elastic Detection Rules

View Source
Summary
Detects curl usage attempting to download an HTTP(S) resource with a short command line (≤5 args) that writes output to a file or is executed under a shell, in a process ancestry that includes Node.js running an npm package (via npx-cli.js or an npx cache path). This pattern is characteristic of malicious npm packages or compromised dependencies that fetch a second-stage payload during install or postinstall scripts. The rule uses ES|QL to (1) identify npm package installs as a parent process (is_pkg_install) when the parent is node and the command line matches npx-cli.js or npm-cache paths, and (2) detect curl downloads (is_curl_download) that contact HTTP(S), have a short arg count, write output via -o/--output, or run under a shell, while excluding loopback/metadata-only URIs. It then intersects the curl process ancestry with known npm-package install entities to determine if the curl activity descended from a package install. When such a relationship is present, the rule emits an alert containing process and host details to facilitate rapid containment and investigation. The investigation guidance emphasizes identifying the npm package involved, examining the download URL and output path, and correlating with recent npm installs or lockfile changes. The rule maps to MITRE ATT&CK techniques: T1105 (Ingress Tool Transfer/Download), T1059 (Command and Scripting Interpreter) with Unix Shell subtechnique, and T1195 (Supply Chain Compromise) with T1195.001 (Compromise Software Dependencies and Development Tools). Triage and remediation steps include isolating the host, terminating the related process tree, removing the package and dropped files, rotating credentials/tokens (including npm tokens and cloud keys), and blocking the package and related domains while hunting for other instances across hosts.
Categories
  • Endpoint
  • Linux
  • macOS
Data Sources
  • Process
  • Command
  • File
ATT&CK Techniques
  • T1105
  • T1059
  • T1059.004
  • T1195
  • T1195.001
Created: 2026-09-23