A supply-chain incident made an AI coding blind spot visible
Large consumer marketplace Workforce coding agents
Their EDR had no record of the activity. Geordie had recorded the agent session itself.
In summer 2026, a developer’s Claude Code session ran a routine dependency update. The agent pulled in a malicious npm package linked to the Shai Hulud supply-chain worm.
The customer treated it as a P0 compromised-package incident.
Their EDR had no record of the activity. It did not capture the npm or npx commands run inside the agent session. It did not raise an alert. As the customer put it in the incident review: “There’s no telemetry in EDR.”
Geordie had recorded the agent session itself. The incident response team could see the exact command and tool calls the agent made. That gave them evidence of what happened inside the coding agent, where their existing endpoint tools had no visibility.
The incident changed who needed Geordie’s data. IR and SOC teams joined the relationship directly, and the customer asked for detections they could send into its SIEM and SOAR workflows. Geordie also became a key data source for the customer’s AI SOC initiative.
What this enabled
The customer could treat AI coding agents as active systems in the developer environment, with their own actions, tool use, and supply-chain exposure.
That creates a practical basis for expanding workforce agents without relying on endpoint telemetry alone. The same model can support Claude Code, Claude Cowork, and Codex as they enter more workflows. It can also extend to custom agents running in internal harnesses, and to cloud and SaaS agents where organizations need to understand what an agent did before deciding how to govern it.
AI agents now run installs and execute code on developer machines. Agent activity is part of the supply-chain risk picture. It needs evidence of its own.