AI Cyber Security

Aikido Security Launches Aikido Endpoint — Putting a Security Layer Between the Open Internet and Every Developer Device as Supply Chain Attacks Hit Unprecedented Scale

AI  /  Cyber Security  |  4 min read


Aikido Security (Ghent, Belgium; the fastest European cybersecurity company to reach unicorn status; co-founder and CEO Willem Delbare; 100,000+ teams; customers including the Premier League, Revolut, SoundCloud, and Niantic), has launched Aikido Endpoint — a lightweight security agent that protects developer devices against software supply chain attacks by inspecting and blocking risky packages, IDE extensions, browser plugins, and AI tools before they are ever installed. The launch arrives at the close of what the company describes as the worst stretch of supply chain compromises in open source history. In March 2026 alone, the threat group TeamPCP chained stolen credentials across four major projects — Trivy, Checkmarx KICS, LiteLLM, and Telnyx — in under ten days. Days later, Axios — the most widely used HTTP client in JavaScript with over 100 million weekly downloads — was compromised separately through a hijacked maintainer account. Every one of these attacks targeted the same thing: the developer device itself.

"The developer device is the Achilles' heel of the software supply chain. These machines hold the credentials, the publish tokens, and the keys to production. Most organisations have zero visibility into what's being installed on them — by human or agent. Endpoint puts a security layer between the open internet and every developer machine in the company."

— Willem Delbare, Co-founder and CEO, Aikido Security

The AI-Accelerated Threat — 100,000 Malicious Packages Per Day and an $8 Attack

The supply chain threat is compounding on two fronts simultaneously. On offence, the barrier to writing supply chain malware has collapsed — AI has lowered the skill requirement for crafting sophisticated attacks to the point where a basic subscription to a consumer AI chatbot is sufficient. On the endpoint itself, AI coding agents are now pulling packages, utilising tools, and adding dependencies autonomously — multiplying the attack surface on developer machines in ways that no human review process can keep pace with. Aikido Intel, the company's threat intelligence engine, now identifies over 100,000 malicious packages per day across open source registries — up from roughly 20,000 a day a year ago. Existing supply chain security tools focus on code repositories, CI/CD pipelines, or individual package managers. Aikido Endpoint works differently: it sits on the device itself and monitors every install across the entire machine — npm, PyPI, Maven, NuGet, VS Code extensions, browser plugins, AI tools, and MCP servers — blocking threats before they reach the filesystem.

"Writing a supply chain attack used to require real skill. Now you need an $8 ChatGPT subscription. In twelve months, we went from single-package compromises to self-replicating worms to full CI/CD pipeline hijacks chaining across registries. Aikido Endpoint is built for this new reality."

— Charlie Eriksen, Lead Security Researcher, Aikido Security

Aikido Endpoint — How It Works and the 48-Hour Rule

Before any package, IDE plugin, browser extension, or AI tool is installed, Endpoint's agent inspects it against Aikido Intel's continuously updated threat feed — blocking known malware automatically before it touches the filesystem. Any package published less than 48 hours ago is automatically blocked, closing the highest-risk window when newly malicious packages are most likely to be distributed before the security community detects them. In the Axios attack, the malicious dropper dependency was pre-staged less than 24 hours before compromised versions pulled it in — the 48-hour age check alone would have blocked the infection. Endpoint is deployed through existing MDM controls — no new tooling infrastructure required — and provides governance controls, request-and-approval workflows, granular access controls (which teams can install what), an AI tool visibility and cost tracking layer, and a full audit trail covering every developer device in the organisation. For developers, Aikido Endpoint is designed to disappear: clean installs go through without interruption, tickets, or delay. If something is malicious, it is blocked before it touches the machine. Aikido Endpoint builds on Safe Chain — Aikido's open-source CLI firewall with over 200,000 weekly downloads — elevating its protection from CLI-level to full device-level coverage across every package manager and marketplace.

"Enterprises are rolling out AI coding tools to thousands of developers with little to no visibility and control of what is really running on developer workstations. Our approach to self-securing software builds the guardrails for this new era of development by protecting not just the code that is being shipped, but also the environment where it's generated."

— Willem Delbare, Co-founder and CEO, Aikido Security

Key Takeaways

  • Aikido Security (Ghent, Belgium; co-founder and CEO Willem Delbare; fastest European cybersecurity company to reach unicorn status; 100,000+ teams; Premier League/Revolut/SoundCloud/Niantic) has launched Aikido Endpoint — announced 20 April 2026. A lightweight security agent protecting developer devices against supply chain attacks by inspecting and blocking risky packages, IDE extensions, browser plugins, and AI tools before installation. Context: worst stretch of supply chain compromises in open source history — March 2026 saw TeamPCP compromise four major projects (Trivy/Checkmarx KICS/LiteLLM/Telnyx) in under ten days, followed by the Axios HTTP client compromise via hijacked maintainer account (100M+ weekly downloads).
  • Why the developer device is the target: developer machines hold cloud credentials, npm publish tokens, SSH keys, Kubernetes configs, and direct access to source code — the highest-value assets in the software supply chain. AI coding agents (Cursor, Windsurf, Claude Code, Codex, Copilot) are now pulling packages and adding dependencies autonomously, multiplying the attack surface without human review. Traditional EDR misses npm install; MDM does not understand what an MCP extension does. Aikido Intel identifies 100,000+ malicious packages per day — up from 20,000 a year ago. AI has lowered the barrier to writing supply chain malware to an $8 consumer AI subscription.
  • How Aikido Endpoint works: sits on the device (not just the CI/CD pipeline or code repo) and monitors every install across the machine — npm/PyPI/Maven/NuGet/VS Code/Chrome/AI tools/MCP servers. Checks every package against Aikido Intel's continuously updated threat feed before it touches the filesystem. 48-hour minimum age rule: automatically blocks any package published less than 48 hours ago — closing the highest-risk attack window (the Axios malicious dropper was pre-staged less than 24 hours before compromised versions pulled it in; the age rule alone would have blocked infection). Deployed via existing MDM controls — no new infrastructure required. Designed to be invisible to developers: clean installs pass without delay.
  • Enterprise governance capabilities: granular access controls (which teams can install what); request-and-approval workflows for blocked packages; full audit trail; AI tool visibility and cost tracking (which AI models and services are running across developer workstations + usage monitoring + cost tracking); central dashboard. For security teams: visibility and control without slowing down development. Builds on Safe Chain (Aikido's open-source CLI firewall; 200,000+ weekly downloads) — Safe Chain protected against Shai-Hulud, TeamPCP, and Axios attack patterns; Endpoint is the enterprise-grade evolution covering every package manager and marketplace, deployed via MDM.
  • Strategic positioning: Aikido Endpoint addresses the specific gap created by AI-native development — a gap that neither traditional EDR (built for signed binary/OS attacks) nor MDM (built for device management, not package intelligence) was designed to fill. As enterprises roll out AI coding tools to thousands of developers simultaneously, the attack surface on developer workstations is expanding faster than any previous tooling cycle. Aikido's self-securing software approach positions Endpoint as the security layer for the AI coding era — protecting not just the code being shipped but the environment in which it is generated. The LiteLLM compromise in March 2026 (a package central to AI model interactions) demonstrated that supply chain attackers are now deliberately targeting AI development toolchains as the highest-leverage entry point.
Tags: AI News Cyber Security Supply Chain Security AI Tech Trends Developer Tools Artificial Intelligence News