Cycode Extends Security to Developers' Workstations
News related to:Cycode · 3 min read
SAN FRANCISCO, Sept. 23, 2026 /CourierPR/ -- Cycode, the leader in Agentic Development Security, has introduced Workstation Protection for developers, providing real-time protection to every developer workstation. This new capability closes the gap between the speed of AI risk and the speed of AI security by blocking malicious packages before they are installed.
Cycode’s ADLC Protection system intercepts package installs in real time and evaluates them before they reach the machine, applying two controls: enforcing cooldown policies and blocking known-malicious packages. Enforcing cooldown policies involves release-age gating, which refuses versions published too recently to have been scrutinized, the window in which compromised releases are most often caught. This policy holds regardless of the package manager version a developer or agent is running or whether a local configuration was ever applied. Blocking known-malicious packages involves checking each install against a continuously updated threat intelligence feed. Confirmed-malicious packages are stopped regardless of when they were published, including older versions and those that have already aged past a cooldown window.
The release of Cycode’s Workstation Protection comes as software supply chain attacks have increasingly targeted developers' workstations, installing malicious packages to harvest credentials, establish persistence, and compromise the supply chain before a single line of code is generated. These attacks have grown more prevalent as attackers exploit two weaknesses: hijacking maintainer accounts to weaponize trusted open-source packages and manipulating coding agents into installing malicious packages. Recent attacks include Keyv, in August 2026, which involved a hijacked maintainer account seeding a preinstall worm across 800+ packages and 1,300+ versions, representing more than two billion monthly installs, and harvesting cloud and CI credentials. Another attack, LiteLLM, in March 2026, involved two malicious packages in a library with 95 million monthly downloads that triggered credential theft, Kubernetes lateral movement, and a persistent backdoor. A third attack, Shai-Hulud 2.0, in November 2025, saw a self-replicating npm worm reach roughly 350 maintainers and exfiltrate secrets to more than 25,000 attacker-created GitHub repositories.
Cycode’s Workstation Protection deploys through Mobile Device Management, adding no console or infrastructure and changing nothing about how developers install packages. Security teams define and manage cooldown policies centrally, so protection extends to every developer workstation running a coding agent as quickly as software can be pushed to it. Workstation Protection extends Cycode’s ADLC Security, which covers each moment risk enters agentic development. It begins on the device, where malicious packages install before a line of code is written. It continues into the AI tools developers adopt, where visibility and governance surface shadow AI, coding assistants, and MCP servers, and control what is permitted. It reaches the prompt, where guardrails stop risky behaviors like exposing secrets in prompts and file reads. And it extends into the code agents generate, which Cycode secures before it ships.
Cycode’s Workstation Protection is now available in early access. To learn more, visit cycode.com/blog/introducing-workstation-protection.
Cycode is the only Complete Agentic Development Security Platform, securing AI development from prompt to runtime. Unlike standalone models and frontier lab tooling that only run when invoked on their own, Cycode is Always-On™. By unifying control, context, and autonomy in a single platform, with ADLC Security built in, Cycode continuously identifies risk across the AI development lifecycle, governs the AI tools developers use, correlates context across the entire software factory, and deploys and manages agents that prevent risk at AI speed. Cycode secures the top Fortune 500’s and is recognized as a Leader by the industry’s top analyst firms, including the Gartner® Magic Quadrant™ for Application Security Testing, the Gartner® Magic Quadrant™ for Software Supply Chain Security, and the IDC MarketScape for ASPM. Learn more at cycode.com.