CrowdStrike has introduced a new supply chain security capability designed to stop malicious open-source packages at the endpoint before they can execute, targeting a growing risk as AI coding agents accelerate software development.
The company’s Real-Time Supply Chain Attack Protection intercepts package manager transactions such as `npm install` and `pip install` across Windows, macOS, and Linux, blocking packages before embedded scripts can execute.
CrowdStrike said AI coding agents are increasingly assembling applications from packages pulled from public registries at machine speed, creating a wider attack surface that extends beyond traditional developer workstations.
“Attackers know that compromising one trusted package can give them a path into thousands of organisations. That makes the software supply chain one of the most powerful attack surfaces in the AI era,” Michael Sentonas, president of CrowdStrike, said in a statement.
“The endpoint is where malicious code executes, and only CrowdStrike turns it into the control point that stops the attack.”
The company pointed to recent examples of adversaries targeting software dependencies, including DPRK-linked actor STARDUST CHOLLIMA, which CrowdStrike said poisoned 131 trusted AI framework packages. It also said eCrime actor ALTERED SPIDER – also known as TeamPCP – compromised more than 300 software dependencies in a single day.
The AFP recently arrested two Western Australian men with links to the hacking group.
CrowdStrike argues that the traditional software supply chain security model is increasingly inadequate because poisoned packages can appear to be legitimate files and execute code during installation. As AI agents operate across more parts of the enterprise, any endpoint could potentially download a package to complete a task.
The new capability allows security teams to apply granular controls over packages reaching endpoints, including minimum package-age requirements intended to prevent newly published packages from becoming an immediate attack vector.
CrowdStrike said its Falcon sensor can also automatically investigate a flagged package by conducting a lookback across endpoints and triggering remediation through Charlotte Agentic SOAR.
The platform provides a global inventory of software packages installed across an organisation’s endpoints, allowing security teams to identify where a compromised dependency exists and respond more quickly.
CrowdStrike said protection continues beyond the initial package download, with the Falcon platform able to monitor what a malicious package attempts to do next, including execution, credential access, and lateral movement.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.