These are hard to detect for a few reasons:
- Traditional endpoint protection is often disabled on developer machines
- Developers require much more access to their machines to do their jobs
- Installing packages in most programming languages still results in RCE at install time
- Most solutions are aimed at protecting code once it makes it to CI and production, but developer machines are still the wild west
If you're not already operating in a world where you assume every developer laptop is compromised, you need to start. The only real protection here is requiring multi-party review for *everything*.