Crowdstrike Holdings IncCrowdStrike launches new Falcon platform innovation for real-time supply chain attack protection.

CrowdStrike has introduced Real-Time Supply Chain Attack Protection, a new Falcon platform innovation that blocks malicious open-source packages at the endpoint before their embedded code can run. The company announced the product at its Fal.Con 2026 conference in Las Vegas. CrowdStrike's 2026 Threat Hunting Report found that DPRK-nexus adversary STARDUST CHOLLIMA poisoned 131 trusted AI framework packages, while eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day. The new protection intercepts package manager transactions such as npm install and pip install across npm and PyPI on Windows, macOS, and Linux, and extends to every endpoint where agentic applications run. Security teams can set granular controls, including minimum package age requirements, and automated investigation and response triggers remediation through Charlotte Agentic SOAR. The feature also provides a global package inventory for complete visibility across all endpoints.
Crowdstrike Holdings IncCrowdStrike launches new Falcon platform innovation for real-time supply chain attack protection.
Microsoft Corporation