
Summary
This ES|QL rule, titled “Suspicious PowerShell from npm Package Install,” detects PowerShell activity that is launched with an encoded command or a download cradle and that sits within a process ancestry including Node.js executing an npm package (notably via npx-cli.js with a scoped or versioned package). The detection logic first flags npm/npx-based package executions by identifying a PowerShell process whose ancestry contains a node.exe parent running npx-cli.js, npm-cli.js, or npm-cache paths. It then flags PowerShell invocations that use encoded commands (-EncodedCommand, -Enc, -ec, or fromBase64) or “download cradle” techniques (downloadstring, Invoke-WebRequest, IEX, Start-BitsTransfer, WebClient, etc.). The rule aggregates all npm package install events on the host (collecting parent process IDs and command lines for npm installs) and computes the intersection between these package-install ancestors and the current PowerShell process ancestry. If a match is found, the event is considered suspicious. The rule emits key telemetry (host, user, process details, and flags for is_encoded_powershell and is_download_cradle) to enable rapid investigation. This pattern is aligned with MITRE ATT&CK techniques T1059 (PowerShell), T1195 (Supply Chain Compromise—Compromise Software Dependencies and Development Tools), T1027 (Obfuscated/Encoded Commands), and T1105 (Ingress Tool Transfer). It is designed for Windows endpoints and leverages endpoint data enriched by Elastic Defend. The rule highlights the supply-chain angle of malicious npm packages or compromised dependencies used to drop or execute payloads via PowerShell, and it includes triage guidance for containment, credential rotation, blocking related domains, and hunting for other hosts with similar package-driven PowerShell activity.
Categories
- Endpoint
- Windows
Data Sources
- Process
ATT&CK Techniques
- T1059
- T1059.001
- T1195
- T1195.001
- T1027
- T1027.010
- T1105
Created: 2026-09-22