TL;DR — Key Takeaways
- CrowdStrike introduced Real-Time Supply Chain Attack Protection to block malicious open-source packages at the endpoint before embedded code can execute.
- The capability protects both human developers and AI coding agents by intercepting package manager transactions on Windows, macOS and Linux systems.
- CrowdStrike says the technology gives DevSecOps teams visibility into where compromised packages are installed and can automatically trigger remediation workflows.
CrowdStrike today at its Fal.con 2026 conference extended its reach into the realm of software supply chain security with the addition of an offering that blocks malicious open-source packages at the endpoint before their embedded code can run.
Bartley Richardson, chief AI and autonomous systems officer for CrowdStrike, said Real-Time Supply Chain Attack Protection is designed to prevent both human developers and artificial intelligence (AI) coding agents from downloading malicious software packages that have been poisoned by malicious actors. The only place to effectively thwart these types of attacks is at the command line interface (CLI) running on the endpoint used to build an application, added Richardson.
Based on a sensor that CrowdStrike relies on to secure endpoints, Real-Time Supply Chain Attack Protection intercepts open-source package manager transactions before any embedded script runs on a Windows, macOS or Linux endpoint. DevSecOps teams, as a result, have complete visibility into every software package installed across every endpoint, so when a package is compromised, security teams know exactly where it lives and can act immediately.
Additionally, the moment a package is flagged, CrowdStrike automatically runs a lookback across every endpoint and triggers remediation workflows via its Charlotte agentic AI automation platform.
Finally, every malicious package discovered serves to make Real-Time Supply Chain Attack Protection smarter about what to look for in the next attack, said Richardson.
Software supply chain security is becoming a more pressing concern as adversaries continue to aggressively exploit vulnerabilities found in code. CrowdStrike’s 2026 Threat Hunting Report, for example, found STARDUST CHOLLIMA, a cybersecurity syndicate that operates out of North Korea, has poisoned 131 trusted AI framework packages, while another syndicate dubbed eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day.
The challenge is that poisoned software packages look like any other ordinary file. Once installed, code starts to automatically run, which means that code may not be discovered for days, if ever, by legacy scanning tools. Adding insult to injury, if not stopped at the endpoint before embedded scripts execute, a poisoned package also starts to move downstream as applications are deployed.
More challenging still, AI agents that are becoming more widely deployed are also likely to discover a poisoned package that will then be incorporated into an agentic workflow.
CrowdStrike, in effect, is making a case for using its endpoint security tools to prevent malicious software packages from ever finding their way into the software supply chain in the first place.
It’s not clear to what degree organizations that build software are revisiting their DevSecOps workflows, but it’s apparent that legacy processes need to be updated in the AI era. The challenge is that as it becomes simpler to build and distribute malicious packages, the current state of the art depends far too much on an individual developer to distinguish between one file versus another in what has become a sea of them.
Frequently Asked Questions
What is CrowdStrike Real-Time Supply Chain Attack Protection?
It is a security capability designed to intercept and block malicious open-source software packages at the endpoint before embedded scripts can execute.
Who does the technology protect?
It is designed to protect both human software developers and AI coding agents that download and use open-source packages.
How does CrowdStrike block malicious packages?
The technology monitors package manager transactions at the endpoint and prevents suspicious or malicious packages from executing embedded code.

