CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks

Real-Time Supply Chain Attack Protection, embedded into the Falcon sensor, blocks malicious open-source packages at download to secure the endpoint as the primary enforcement point where AI operates.

Software supply chain attacks pose a critical enterprise threat. In the first half of 2026, these attacks increasingly used malicious software packages uploaded to public software registries, the CrowdStrike 2026 Threat Hunting Report found.

Adversaries are poisoning open-source packages and exploiting the same dependencies that AI-assisted development tools and agentic applications pull onto enterprise endpoints every day. The endpoint is where those malicious packages land, execute, and need to be stopped.

CrowdStrike is advancing endpoint security with Real-Time Supply Chain Attack Protection, a capability natively embedded in the lightweight CrowdStrike Falcon® sensor. It detects and blocks malicious open-source packages as they reach the endpoint, before any embedded code can execute, and provides a global inventory of installed packages across the organization. It requires no new sensor deployment, separate tool, or changes to developer workflows.

The Problem Extends Beyond Developer Workstations

When most organizations think about software supply chain risk, they think about developers running npm install or pip install on their workstations. That is a critical surface, but the picture has gotten much larger.

In the AI era, everyone is a developer. Agentic applications like Claude Code and ChatGPT Codex are now used across marketing, HR, finance, and operations teams. These tools automate tasks, generate content, and build internal workflows. When an agentic application recommends downloading a package to complete a task, employees across the business may unknowingly expose their endpoints to compromised dependencies. The attack surface has expanded from a few hundred developer machines to potentially every company endpoint.

Adversaries are capitalizing on this expanded surface, as documented in the CrowdStrike 2026 Threat Hunting Report: STARDUST CHOLLIMA poisoned 131 AI framework packages, which are trusted building blocks that can inherit access to sensitive enterprise assets and become attack paths for credential theft and persistence. ALTERED SPIDER compromised more than 300 software dependencies in a single day, spreading poisoned packages at scale and turning trusted code into downstream supply chain compromise.1

How Real-Time Supply Chain Attack Protection Works

Real-Time Supply Chain Attack Protection extends the Falcon sensor’s visibility and control to non-executable software packages. When a package manager transaction is initiated, the Falcon sensor intercepts the download and evaluates suspicious files against CrowdStrike Falcon® Adversary Intelligence. If a match is found, the sensor immediately quarantines the file before any embedded setup script can execute.

This is modern endpoint security doing what endpoint security does best: seeing and stopping threats where they land. The same unified sensor, already deployed, already protecting the fleet, now covers packages too, whether they’re downloaded by a human or an AI agent.

Key capabilities include:

  • Continuously monitor package activity: The Falcon sensor maintains a constant watch over package downloads across npm and PyPI on Windows, macOS, and Linux, closing critical entry-point blind spots and giving security teams visibility into active, incoming code across the enterprise fleet.
  • Stop malicious packages at download: The Falcon sensor automatically detects and quarantines compromised packages the moment they are written to disk, neutralizing threats before malicious embedded scripts have a chance to execute. This is real-time prevention, not after-the-fact detection that requires a separate response workflow to contain damage.
  • Automate fleet-wide investigation: The moment a new package is flagged as compromised, the Falcon platform instantly runs an intelligent lookback query across enterprise data. If a historical match is discovered, automated containment workflows isolate the threat and remediate affected endpoints, minimizing manual analyst triage.
  • Gain full visibility with global package inventory: Falcon provides comprehensive visibility into software packages installed across the enterprise fleet, helping security teams understand package relationships and identify where risky versions reside, directly from the unified Falcon console.
  • Implement proactive policy controls and cooldown protection: Falcon reduces software supply chain risk with granular, risk-based controls including minimum package age requirements, restrictions on publicly available packages, and automated fallbacks to approved versions. Security teams gain proactive governance over what code reaches their endpoints.

Watch how it works:

Proactive Protection: Control and Cooldown

Beyond real-time detection and prevention, CrowdStrike is delivering granular policy controls that address a well-documented pattern: The first few days after a new package version is released represent a critical risk window, before malicious versions are widely identified and removed. Freshly published packages carry the highest risk because they have undergone the least community scrutiny.

Proactive policy controls allow security teams to enforce minimum package age requirements before a package can be installed on a protected endpoint, effectively placing new and untrusted packages in a cooldown period. Organizations can also restrict access to publicly available packages or redirect users to approved, vetted versions. This gives security teams governance over what code reaches their endpoints while preserving productivity. Proactive policy controls are set to be released in Q4.

Global Package Inventory

Visibility is a prerequisite for control. Real-Time Supply Chain Attack Protection provides a comprehensive global inventory of installed software packages across the enterprise via CrowdStrike Falcon® Exposure Management, enriched with CrowdStrike Counter Adversary Operations intelligence. Security teams can understand package relationships, identify where risky package versions reside across the fleet, and take action from the same unified console they already use for endpoint protection. This inventory spans the entire managed fleet, covering every endpoint where packages are present, including the non-developer machines that developer-only solutions cannot see. Global Package Inventory is set to be released in Q3.

Unified Through the Falcon Platform

Real-Time Supply Chain Attack Protection ships through the existing Falcon sensor. There is nothing additional to deploy, no developer workflow to change, and no separate console to manage. Organizations that already run the Falcon sensor gain supply chain protection by enabling a policy.

Our single-sensor architecture stands in sharp contrast to the alternative: deploying a separate developer workstation sensor from one vendor, a supply chain scanner from another, and still having no coverage for the majority of endpoints where agentic applications are actively downloading packages. The Falcon sensor already protects the fleet. Real-Time Supply Chain Attack Protection extends that protection to the package layer for every endpoint, with real-time blocking and automated remediation built in from Day One.

As adversaries continue to weaponize the software supply chain at scale, defenders need real-time enforcement at the point of impact. Real-Time Supply Chain Attack Protection puts that enforcement exactly where it belongs: at the endpoint, at the moment of download, before code executes.

Additional Resources

Disclaimer

This blog includes discussion of unreleased services or features. Any unreleased services or features referenced here are still in development and subject to change. Customers should make their purchase decisions based upon features that are currently available.

1 CrowdStrike 2026 Threat Hunting Report


CrowdStrike Falcon Platform
Ready to protect your business?

Try CrowdStrike free today

Subscribe

Sign up now to receive the latest notifications and updates from CrowdStrike

See CrowdStrike Falcon in action