Workstation Protection builds on the AI visibility, governance, and guardrails of the Cycode platform, blocking malicious packages and enforcing cooldown policies on developers’ workstations in real time.
Software supply chain attacks are intensifying and moving upstream to every workstation running a coding agent. Two things drive this escalation. Attackers have recognized the widespread impact of compromising trusted open-source packages and are increasingly targeting maintainer accounts. And coding agents install dependencies at machine speed on far more devices. The result is more potent threats against a wider attack surface.
Cycode Workstation Protection extends Agentic Development Lifecycle (ADLC) Security upstream to stop software supply chain attacks where they start: the developer device. It intercepts package installs in real time and applies two controls: enforcing cooldown policies for age-related gating and checking against threat intelligence to block known malicious packages. Cycode now secures the full AI software supply chain, from packages to prompts to pipelines.
Attacks have moved to the install and developer workstation.
Earlier supply chain campaigns targeted the pipeline. SolarWinds compromised a build process, Codecov harvested CI secrets, CircleCI showed how a stolen engineer session could expose customer tokens. The current generation of supply chain attacks moves upstream. A poisoned dependency runs its code the moment it installs on a developer workstation, harvesting credentials, establishing persistence, and reaching the systems that machine can access, all before a line of code is committed or a security control has anything to inspect. Some variants take the compromise a step further, using any package-publishing access they uncover to release malicious versions of additional packages the victim controls, extending the attack further into the ecosystem.
At the same time, coding agents are susceptible to installing malicious packages and present attractive targets. They perform hundreds of actions with minimal human review, have credentials, and often circumvent traditional security controls. The S1ngularity software supply chain attack shipped packages that, per the maintainers’ postmortem, attempted to use local AI tools like Claude and Gemini to hunt for sensitive information on the machines they landed on.
Recent campaigns show how routine these attacks have become:
- Keyv, August 2026. A hijacked maintainer account seeded a preinstall worm across 800+ packages and 1,300+ versions, representing more than two billion monthly installs, harvesting cloud and CI credentials.
- LiteLLM, March 2026. Attackers published two malicious versions of a library with 95 million monthly downloads, triggering credential theft, Kubernetes lateral movement, and a persistent backdoor.
- Shai-Hulud 2.0, November 2025. A self-replicating npm worm reached roughly 350 maintainers and exfiltrated secrets to more than 25,000 attacker-created GitHub repositories.
Each campaign compromised a maintainer account, a publishing token, or a release workflow, then poisoned trusted packages to ship malware. And every one executed on a developer workstation before a security review ran.
How Cycode Workstation Protection stops supply chain attacks
Workstation Protection makes the install command an enforcement point. The lightweight control deploys via Mobile Device Management (MDM), evaluates packages in real time, enforces cooldown policies, and blocks malicious packages before they install. There is no new console, no new infrastructure, and no change to how anyone installs a package. Security teams define cooldown policies centrally, and protection reaches every developer workstation.
Cooldown policies and malicious package threat intelligence work in concert to stop the recent pattern of software supply chain attacks.
Cooldown policies protect from recently compromised packages
The most immediate mitigation is release-age gating, often called package install cooldown. The idea is simple: refuse to install recently published packages before maintainers and security researchers have time to identify and flag malicious versions.
This is not only about blocking brand-new packages. It applies to newly published versions of packages developers already trust. Many attacks do not create a new package. They compromise an existing one and ship a malicious version under a familiar name. A cooldown window gives the ecosystem time to detect, report, and remove that version.
Cooldown policies are effective controls that meaningfully reduce exposure during the period when a newly published version is hardest to trust and should be enabled wherever your package manager supports it. Cycode Workstation Protection enforces cooldown policies on the device, so it holds regardless of which package manager version a developer or agent happens to be running, or whether a local config file was ever set up correctly.
Malicious package detection catches what cooldown policies leave open
Cooldown policies provide a strong baseline but will not stop every attack. Not every package manager supports release-age gating, and cooldown policies do not block a malicious package that has aged past the window.
To address these gaps, Cycode also checks every package against a continuously updated threat intelligence feed. This protects against persistent malicious packages, a compromised maintainer account that keeps shipping bad versions over time, or a typosquatting or slopsquatting attack with a long-lived malicious package with a name intended to trick developers and agents into unwittingly installing it.
Cooldown buys time for the ecosystem to catch a bad release. Threat intelligence acts on what the ecosystem has already caught. Run together at the install command, they turn the workstation from a blind spot into an enforcement point.
Unified security across the ADLC
The install is where risk first enters the ADLC. It is not where risk stops. The same workstation that pulled a package also runs the AI tools an employee adopted without telling anyone, and sends the prompts that expose secrets out to a model. Cycode discovers and governs those tools, including shadow AI, coding assistants, and MCP servers, with full AI Bill of Materials coverage, and applies guardrails that stop secrets and sensitive context from leaving in prompts and file reads.
From there, risk follows the code. Cycode validates the code agents generate and the dependencies they pull in, enforces pipeline integrity, and catches exposed secrets and misconfigurations across the software factory.
Covering each stage matters because attacks move across them. A malicious package on a workstation reaches a credential, that credential reaches a repository, and that repository reaches a pipeline with publish rights. Separate tools at each stage struggle to link connected events. Cycode resolves every signal in the Context Intelligence Graph, so the relationships between them are clear and security teams can prevent, manage, and reduce the risks that matter.
Workstation Protection is available in early access. Schedule a demo to learn more.
