CrowdStrike Adds Real-Time Supply Chain Attack Protection

CrowdStrike adds real-time software supply chain protection that blocks malicious packages at endpoints before embedded scripts can execute.

Written By
Jordan Smith
Jordan Smith
Sep 3, 2026
2 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

CrowdStrike has introduced Real-Time Supply Chain Attack Protection at Fal.Con 2026, a new capability designed to stop malicious software packages at the endpoint before embedded scripts can execute.

The launch comes as AI coding agents accelerate developers’ use of open-source packages and dependencies, creating new opportunities for attackers to compromise software components before they reach production environments.

CrowdStrike targets software supply chain risk from AI coding

AJ Shipley, Chief Product Officer at CrowdStrike, says that coding agents are accelerating the adoption of open-source packages and dependencies, while adversaries are increasingly exploiting that speed to poison software components.

“AI has fundamentally changed how software gets built,” Shipley noted. “Coding agents are now staples on every developer’s workstation. We use them at CrowdStrike. They’re able to assemble applications from open-source packages, pulled off of public repositories, and this common theme here of at machine speed. And really, nobody’s reviewing what’s coming on.”

Endpoint becomes the last checkpoint for malicious packages

Malicious packages ultimately have to execute somewhere, making the endpoint a critical control point. Compromised packages can initially appear to be ordinary files before their embedded scripts execute.

“This is an endpoint problem. Again, no surprise. A poison package lands on the endpoint as an ordinary file, and then it runs its embedded scripts the moment it installs,” said Shipley. 

“The endpoint is the point of execution. It’s kind of the last checkpoint, if you will. If it’s not caught there, a poison package is just going to move downstream, giving adversaries a foothold.”

CrowdStrike blocks packages before scripts execute

CrowdStrike’s approach intercepts package-manner transactions at the command line before embedded scripts can execute. It’s an extension of existing endpoint protection rather than requiring another agent or proxy.

“CrowdStrike’s Real-Time Supply Chain Attack Protection stops those malicious packages. The moment that they reach the endpoint, we intercept them at the command line before any embedded script runs,” said Shipley.

Advertisement

“None of this requires a new endpoint agent. This all works with the existing single sensor approach that CrowdStrike has. No proxy, no coverage gaps.”

New controls add package governance and automated remediation

The system provides granular controls over which software packages can access endpoints, along with the ability to perform lookbacks and automatically remediate packages if they are later identified as compromised.

“Security teams get this granular control to govern what code reaches their endpoints, including things like the minimum age of a package before we will allow that package to be downloaded,” said Shipley. 

“And the moment the package is flagged, you can automatically run a look back across every endpoint and trigger remediation actions automatically.”

CrowdStrike has a slate of announcements throughout the week as it convenes partners and customers for its annual Fal.Con event. We’ll continue to cover that news and why it matters to the channel.

Jordan Smith

Jordan Smith is an enterprise technology and cybersecurity journalist with nearly a decade of experience covering B2B IT, federal technology, artificial intelligence, cybersecurity, cloud computing, and emerging digital trends. His reporting helps business and technology leaders understand how new technologies, security challenges, and infrastructure decisions affect modern organizations. Jordan has reported on enterprise and public-sector technology for TechnologyAdvice, HCLTech, MeriTalk, and Channel Insider. His background spans cybersecurity, cloud infrastructure, AI adoption, digital transformation, and federal IT initiatives, giving him a broad perspective on the tools, policies, and innovations shaping today’s technology landscape. Before joining TechnologyAdvice, Jordan served as a Senior Technology Reporter at MeriTalk, where he covered the federal IT space, and later worked as a US Regional Reporter and Copy Editor/Writer for HCLTech. His experience across reporting, copyediting, podcasting, and event moderation allows him to translate complex technical topics into clear, timely, and useful insights for business audiences. Jordan holds a Master of Arts in Journalism from the University of Nebraska–Lincoln and a Bachelor of Science in Criminal Justice and Psychology from Edgewood University. Through his work, he helps readers stay informed about cybersecurity developments, enterprise technology trends, and the business impact of emerging IT solutions.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.