CloudSecurity

Introducing the Wiz Sensor for Developer Workstations to Protect Endpoints in the AI Era


Developers hold cloud credentials, npm publish tokens, and direct access to source code, and their work requires installing packages and running third-party code on their workstations. AI coding agents now do the same at machine speed. As AI expands who builds software, others are joining that group, each pulling packages, IDE extensions, and AI tools onto workstations that reach directly into cloud environments and deployment pipelines. According to Wiz’s State of SDLC Security 2026 report, 71% of organizations have at least one AI coding assistant present and 80% use AI IDE extensions, each writing code, calling APIs, and accessing credentials autonomously.

That expanded access has made the developer workstation an increasingly attractive target in the software supply chain. Wiz Research documented campaigns including Shai-Hulud, Axios, and s1ngularity, each starting at the developer workstation, using malicious packages and compromised IDE extensions to harvest credentials and reach cloud environments, registries, and production systems. Those attacks are accelerating. Attackers are now using AI to automate campaigns, scale targeting, and exploit the fact that coding agents operate with full developer permissions at machine speed.

What makes these attacks hard to stop is that traditional endpoint detection was built to identify malicious behavior and stop endpoint compromise, not to continuously understand the developer ecosystem: which packages, IDE extensions, and AI coding agents are running, and how they connect to credentials, source code, and cloud environments within reach.

Today, Wiz is announcing the Wiz Sensor for Developer Workstations on Windows and macOS in Private Preview. The Sensor gives security teams continuous visibility into every package, IDE extension, and AI tool running across their developer fleet, real-time detection and automated response for supply chain attacks, and the AI governance every organization needs to manage how builders use AI.

The Attacks That Made the Developer Workstation Impossible to Ignore

Over the past year, Wiz Research has tracked, analyzed, and disclosed a rising wave of supply chain attacks targeting developer workstations. That research is what shaped the Wiz Sensor for Developer Workstations. The campaigns share a common pattern: attackers poisoning trusted packages to exploit developer workstations. 

  • Shai-Hulud, the first self-propagating npm worm, exploited the fact that developer workstations store npm credentials in plaintext. The moment a developer ran npm install, a postinstall script executed TruffleHog directly on their workstation, found tokens, and then used those tokens to republish the worm across every package that developer maintained.

  • Axios, downloaded 100 million times per week, was backdoored through a compromised maintainer account. Within 1.1 seconds of npm install, malicious code injected into a dependency executed on the developer’s workstation and established a C2 connection silently.

  • s1ngularity compromised multiple versions of the Nx build system and its VS Code extension. A postinstall script harvested GitHub tokens, npm credentials, SSH keys, and cloud credentials from developer workstations, then weaponized AI CLI tools already on the machine, including Claude and Gemini, to exfiltrate filesystem contents. Over 1,000 GitHub tokens were leaked and stolen credentials exposed 5,500 private repositories.

The Shai-Hulud attack poisoned packages, ran TruffleHog to exfiltrate secrets, and self-propagated with any new npm tokens the attacker found.

All three attacks followed the same pattern: the developer workstation is where credentials are stored, where untrusted code first executes. As AI and third-party software become standard parts of the developer environment, they operate with developer-level permissions, expanding the ways an attacker can reach what lives on and beyond the developer workstation.

Introducing the Wiz Sensor for Developer Workstations

For the first time, the Wiz Sensor brings developer workstations into the Wiz Security Graph. Deploying via existing MDM solutions, the Sensor gives security teams continuous visibility across the developer fleet, real-time detection when a threat lands on the workstation, and the context to understand what an attacker can reach before they use it.

Stop supply chain attacks at the earliest point of control

See everything on the developer workstation

The Wiz Sensor provides continuous inventory of every package, secret, IDE extension, AI coding agent, and MCP server running across the developer fleet. When a package is identified as malicious, security teams know immediately which workstations are running it.

Detect known malicious packages on install

Wiz Research continuously tracks malicious packages across major registries, combining our own threat research with feeds from leading intelligence providers. Once a package is identified as malicious, it’s added to the Wiz Reputation Database within minutes. When a developer or AI agent installs a known malicious package, security teams get an alert the moment it lands on the workstation. Every detection feeds back into Wiz Defend Threats, continuously enriching the threat context that connects workstation detections to cloud environments and code repositories.

The full process chain from a developer’s workstation to the installation of a malicious package, identifying exactly how the malicious package reached the workstation.

Detect emerging supply chain attacks in real time

Not every malicious package has been discovered yet. In addition to detecting known malicious packages, the Wiz Sensor detects suspicious behavior on the workstation: a postinstall script spawning an unexpected process, TruffleHog scanning credential files, an anomalous outbound connection. Security teams get a real-time alert the moment something executes, with Wiz’s Blue Agent analyzing the threat, classifying it, and recommending immediate response actions. Not days later when credentials start appearing elsewhere.

Blue Agent automatically classifies the threat, summarizes the full attack chain, and recommends immediate response.

Understand the blast radius before an attacker uses it

When a threat is detected, security teams need to know one thing immediately: how bad is this? The Wiz Sensor scans workstations for secrets. Combined with the Wiz Security Graph, security teams can immediately see what each secret discovered on the workstation can access. A stolen PAT surfaces which repositories it can write to and whether any carry npm publish rights. A compromised AWS token surfaces exactly which sensitive resources are within reach. That context is available at detection time, not after a manual triage process.

Wiz maps a single malicious package install to the AWS credentials and environment an attacker could reach.

Respond at the earliest point of control

When Wiz detects a threat, security teams can act at two layers. On the workstation: kill malicious processes and collect forensic artifacts for further analysis. On the cloud side: rotate exposed credentials and revoke compromised tokens before an attacker can use them. The developer workstation is the earliest point in the delivery chain where that level of response is operationally safe, contained enough to protect the organization without risking disruption to production environments and applications.

AI Visibility and Governance for developer workstations

See every AI tool across the developer fleet

The Wiz Sensor provides continuous inventory of every AI coding agent, AI skills, MCP servers, and AI models being used across the developer fleet, alongside the secrets and credentials stored on each workstation. Through the Wiz Security Graph, security teams can see how these components relate to each other and what they can reach: the source code repositories, cloud environments, and sensitive resources within reach.

Wiz maps every AI component running on a developer workstation, including hosted AI agents, MCP servers, AI skills, and coding tools like the Claude Code SDK.

Govern AI across every developer workstation

That visibility is what makes AI governance possible. Toxic combinations that were previously invisible are now surfaced: an unapproved AI tool with access to sensitive cloud credentials, a compromised extension with lateral movement potential, an AI agent operating outside policy. Security teams cannot enforce policy on what they cannot see. With Wiz, teams can define which AI tools are approved, flag unwanted tools like unauthorized MCP servers or coding agents, and use Wiz Workflows to automatically notify engineers when policy is violated.

Wiz surfaces every AI tool running across the developer fleet with approval status, giving security teams the visibility to enforce policy on what is approved, unwanted, or unknown.

Get Started with Wiz Sensor for Developer Workstations

The Wiz Sensor for Developer Workstations is available today in Private Preview for Windows and macOS. If you’re an existing Wiz customer and want to try the Sensor for Workstations, please reach out to your Wiz account manager. For new customers who want to have visibility into AI running on their developer workstations and protect their organizations from supply chain attacks, please reach out to engage with our team today.



Source link