cd /news/ai-safety/cycode-extends-its-adlc-security-cap… · home topics ai-safety article
[ARTICLE · art-138584] src=radicaldatascience.wpcomstaging.com ↗ pub= topic=ai-safety verified=true sentiment=↑ positive

Cycode Extends its ADLC Security Capabilities to Developers’ Workstations, Stopping Software Supply Chain Attacks Before They Start

Cycode announced Workstation Protection, a capability that intercepts package installs in real time on developer workstations and blocks malicious packages before they install, enforcing release-age cooldown policies and checking each install against a continuously updated threat intelligence feed. Cycode President Seth Robbins said the launch extends Cycode's platform to "the workstation, the earliest control point in the software supply chain where malicious packages are installed and must be stopped." The company cited recent supply chain attacks including Keyv in August 2026, which seeded a preinstall worm across 800+ packages and 1,300+ versions representing more than two billion monthly installs, LiteLLM in March 2026 with 95 million monthly downloads, and Shai-Hulud 2.0 in November 2025, which reached roughly 350 maintainers and exfiltrated secrets to more than 25,000 attacker-created GitHub repositories.

by read4 min views1 publishedSep 23, 2026
Cycode Extends its ADLC Security Capabilities to Developers’ Workstations, Stopping Software Supply Chain Attacks Before They Start
Image: Radicaldatascience (auto-discovered)

Workstation protection builds on the AI visibility, governance, and guardrails of the Cycode platform, blocking malicious packages in real time for customers

Cycode, the leader in Agentic Development Security, today announced Workstation Protection for developers, bringing real-time protection to every developer workstation. The new capability closes the gap between the speed of AI risk and the speed of AI security by blocking malicious packages before they install.

Cycode ADLC Protection intercepts package installs in real time and evaluates them before they reach the machine, applying two controls:

  • Enforcing cooldown policies. Release-age gating refuses versions published too recently to have been scrutinized, the window in which compromised releases are most often caught. Because enforcement happens on the device, the policy holds no matter which package manager version a developer or agent is running, or whether a local configuration was ever applied.
  • Blocking known-malicious packages. Each install is checked against a continuously updated threat intelligence feed. Confirmed-malicious packages are stopped regardless of when they were published, including older versions and versions that have already aged past a cooldown window.

AI development increases software supply chain attack risks

Software supply chain attacks increasingly target workstations, installing malicious packages to harvest credentials, establish persistence, and compromise the supply chain before a line of code is generated or a security check runs. These attacks have grown more prevalent as attackers exploit two weaknesses: hijacking maintainer accounts to weaponize trusted open-source packages, and manipulating coding agents into installing malicious packages. The result is more attacks and a wider target. Once limited to developers & their SCM, the attack surface now extends to every developer workstation running a coding agent.

Recent attacks include:

  • Keyv, August 2026. A hijacked maintainer account seeded a preinstall worm across 800+ packages and 1,300+ versions representing more than two billion monthly installs, harvesting cloud and CI credentials.
  • LiteLLM, March 2026 . Attackers published two malicious packages in a library with 95 million monthly downloads that triggered credential theft, Kubernetes lateral movement, and a persistent backdoor.
  • Shai-Hulud 2.0, November 2025. A self-replicating npm worm reached roughly 350 maintainers and exfiltrated secrets to more than 25,000 attacker-created GitHub repositories.

“Risk enters the agentic development lifecycle (ADLC) for our customers before a single line of code is generated. Developers connect AI tools nobody approved, agents install packages nobody reviewed, and secrets leak into prompts and file reads nobody sees,” said Seth Robbins, President of Cycode. “ This launch extends Cycode’s platform to the workstation, the earliest control point in the software supply chain where malicious packages are installed and must be stopped.”

Cycode stops software supply chain attacks before they start

Cycode Workstation Protection deploys through Mobile Device Management, adds no console or infrastructure, and changes nothing about how developers install packages. Security teams define and manage cooldown policies centrally, so protection extends to every developer workstation running a coding agent as quickly as software can be pushed to it.

Workstation Protection extends Cycode ADLC Security, which covers each moment risk enters agentic development. It begins on the device, where malicious packages install before a line of code is written. It continues into the AI tools developers adopt, where visibility and governance surface shadow AI, coding assistants, and MCP servers and control what is permitted. It reaches the prompt, where guardrails stop risky behaviors like exposing secrets in prompts and file reads. And it extends into the code agents generate, which Cycode secures before it ships. Every signal resolves in the Context Intelligence Graph, giving security teams one view of risk across the lifecycle and one place to act on it.

“Security has to start where risk enters the development lifecycle, not after,” said Dor Atias, Co-Founder and Chief Product and Engineering Officer at Cycode. “Blocking malicious packages is the earliest control point in a complete agentic development and software supply chain security solution. Protect every workstation. Control every input. Secure every output. That is what unlocks secure AI development.”

Availability

Cycode ADLC with Workstation Protection is available in early access. To learn more, visit https://cycode.com/blog/introducing-workstation-protection.

							Posted on 09/23/2026, in [AI](https://radicaldatascience.wpcomstaging.com/category/ai/), [AI Industry Latest News](https://radicaldatascience.wpcomstaging.com/category/ai-industry-latest-news/), [News](https://radicaldatascience.wpcomstaging.com/category/news/), [Security](https://radicaldatascience.wpcomstaging.com/category/security/), [Sponsored](https://radicaldatascience.wpcomstaging.com/category/sponsored/), [Uncategorized](https://radicaldatascience.wpcomstaging.com/category/uncategorized/) and tagged [ADLC Protection](https://radicaldatascience.wpcomstaging.com/tag/adlc-protection/), [AI](https://radicaldatascience.wpcomstaging.com/tag/ai/), [Cycode](https://radicaldatascience.wpcomstaging.com/tag/cycode/), [Security](https://radicaldatascience.wpcomstaging.com/tag/security/), [Supply chain](https://radicaldatascience.wpcomstaging.com/tag/supply-chain/). Bookmark the [permalink](https://radicaldatascience.wpcomstaging.com/2026/09/23/cycode-extends-its-adlc-security-capabilities-to-developers-workstations-stopping-software-supply-chain-attacks-before-they-start/).								[Leave a comment](https://radicaldatascience.wpcomstaging.com/2026/09/23/cycode-extends-its-adlc-security-capabilities-to-developers-workstations-stopping-software-supply-chain-attacks-before-they-start/#respond).
── more in #ai-safety 4 stories · sorted by recency
── more on @cycode 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/cycode-extends-its-a…] indexed:0 read:4min 2026-09-23 ·