AI coding agents don't ask permission before running npm install...
…and neither do the malicious packages waiting for them. In 2025 alone, attackers published 454,000+ malicious open-source packages. When your agent autonomously pulls from npm or PyPI, it trusts the registry completely — and that trust is being weaponised at scale. We’ll show how an automated install triggers automated credential theft, and why your existing tools don’t catch it in time.
Learn how to put guardrails on what your agents are allowed to touch with Rubrik Agent Cloud — governing and monitoring agent activity in real time, and, building on the foundation of Rubrik DevOps Protection, rewind an agent’s mistake with a clean recovery from source code backups, stopping the breach before it starts