CrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks CrowdStrike has launched Real-Time Supply Chain Attack Protection, a capability natively embedded in the CrowdStrike Falcon sensor that detects and blocks malicious open-source packages at the endpoint before code execution, addressing the rise in software supply chain attacks that poisoned 131 AI framework packages and compromised more than 300 software dependencies in a single day, according to the CrowdStrike 2026 Threat Hunting Report. Software supply chain attacks pose a critical enterprise threat. In the first half of 2026, these attacks increasingly used malicious software packages uploaded to public software registries, the CrowdStrike 2026 Threat Hunting Report https://www.crowdstrike.com/en-us/resources/reports/threat-hunting-report/ found. Adversaries are poisoning open-source packages and exploiting the same dependencies that AI-assisted development tools and agentic applications pull onto enterprise endpoints every day. The endpoint is where those malicious packages land, execute, and need to be stopped. CrowdStrike is advancing endpoint security with Real-Time Supply Chain Attack Protection, a capability natively embedded in the lightweight CrowdStrike Falcon® sensor. It detects and blocks malicious open-source packages as they reach the endpoint, before any embedded code can execute, and provides a global inventory of installed packages across the organization. It requires no new sensor deployment, separate tool, or changes to developer workflows. The Problem Extends Beyond Developer Workstations When most organizations think about software supply chain risk, they think about developers running npm install or pip install on their workstations. That is a critical surface, but the picture has gotten much larger. In the AI era, everyone is a developer. Agentic applications like Claude Code and ChatGPT Codex are now used across marketing, HR, finance, and operations teams. These tools automate tasks, generate content, and build internal workflows. When an agentic application recommends downloading a package to complete a task, employees across the business may unknowingly expose their endpoints to compromised dependencies. The attack surface has expanded from a few hundred developer machines to potentially every company endpoint. Adversaries are capitalizing on this expanded surface, as documented in the CrowdStrike 2026 Threat Hunting Report https://www.crowdstrike.com/en-us/resources/reports/threat-hunting-report/ : STARDUST CHOLLIMA https://www.crowdstrike.com/en-us/adversaries/stardust-chollima/ poisoned 131 AI framework packages, which are trusted building blocks that can inherit access to sensitive enterprise assets and become attack paths for credential theft and persistence. ALTERED SPIDER https://www.crowdstrike.com/en-us/adversaries/altered-spider/ compromised more than 300 software dependencies in a single day, spreading poisoned packages at scale and turning trusted code into downstream supply chain compromise.