Stop software supply chain attacks
See every package across your fleet and block malicious code before it runs with proactive policy controls.
New from Fal.Con 2026
Software supply chains are under attack
As agentic tools spread beyond developers, software supply chain risk now reaches every endpoint and legacy tools can’t keep up.
The leader in endpoint security extends protection to the software supply chain
Stop packages before code runs
Continuously monitor npm and PyPI package activity across Windows, macOS, and Linux. When a compromised package is downloaded, by a developer or an AI coding assistant like Claude Code or ChatGPT Codex, the CrowdStrike Falcon® platform quarantines it before embedded scripts run. No new sensor, console, or workflow required.
Identify package risk across the fleet
Gain a global inventory of every installed software package across your enterprise. Map package relationships, locate risky versions, and take action from the unified Falcon console through CrowdStrike Falcon® Exposure Management.
Enforce proactive package controls
Reduce supply chain risk before untrusted packages reach your environment. Set minimum package age requirements to block new and risky packages. Restrict access to public repositories, enforce private repository usage, and enable automatic fallback to approved package versions with per-environment policies and clear developer notification.