What happened
On Sept 23, Cycode announced early access to Workstation Protection in its ADLC Protection platform: real-time inspection of package downloads against threat intel plus a cool-down policy blocking recently-updated (unvetted) packages before they reach developer machines or AI coding agents.
Why it matters
AI coding agents increasingly install dependencies autonomously, and attackers are poisoning repos and using malicious prompts to trick agents into pulling compromised packages — install time is now the first supply-chain control point, before any scanner sees code.
Applicability
DevSecOps teams using Cycode should pilot Workstation Protection to enforce package policy at install time, especially where Claude Code/Codex-style agents auto-install dependencies.