started · updated
CrowdStrike launches endpoint protection against supply chain attacks
CrowdStrike has introduced Real-Time Supply Chain Attack Protection, a new capability designed to block malicious open-source packages at the endpoint before embedded code can execute. The feature is natively embedded in the CrowdStrike Falcon sensor and works across Windows, macOS, and Linux systems by intercepting package manager transactions.
The move addresses an expanding threat landscape where adversaries poison open-source packages in public registries. CrowdStrike notes that the attack surface has grown beyond traditional developer workstations to include any employee using AI-assisted development tools and agentic applications, such as Claude Code or ChatGPT Codex, which may unknowingly download compromised dependencies.
According to Bartley Richardson, chief AI and autonomous systems officer at CrowdStrike, the technology provides DevSecOps teams with visibility into installed packages across an organization. When a package is flagged, the system can trigger automated remediation workflows via the Charlotte agentic AI platform.