CrowdStrike has introduced Real-Time Supply Chain Attack Protection, a new capability designed to stop malicious software packages at the endpoint before embedded scripts can execute, according to a recent report by Channel Insider.The new protection comes as AI coding agents accelerate developers' use of open-source packages and dependencies, creating new opportunities for attackers to compromise software components before they reach production environments. AJ Shipley, Chief Product Officer at CrowdStrike, stated that AI coding agents are accelerating the adoption of open-source packages and dependencies, while adversaries are increasingly exploiting that speed to poison software components. The endpoint becomes the last checkpoint for malicious packages, as compromised packages can initially appear to be ordinary files before their embedded scripts execute.CrowdStrike's approach intercepts package-manner transactions at the command line before embedded scripts can execute, extending existing endpoint protection without requiring a new agent or proxy. The system provides granular controls over which software packages can access endpoints, along with the ability to perform lookbacks and automatically remediate packages if they are later identified as compromised.Source: Channel Insider