A wave of self-replicating supply chain worms (Miasma, Hades, Shai-Hulud) has been hitting npm and PyPI, compromising trusted packages to steal developer secrets and publishing tokens. The core problem is that even when organizations configure internal registries and cooldown policies, individual developer machines often drift off the protected path via project-level .npmrc overrides, missing cooldown support, or hardcoded credentials. StepSecurity's new Package Configs feature (part of Dev Machine Guard) audits every developer machine in a fleet to surface: which registry each machine actually resolves from, whether a cooldown policy is in effect, and whether registry credentials are hardcoded in config files versus safely stored in environment variables. This gives security teams a concrete, actionable view of configuration gaps across the entire fleet so they can close the specific weaknesses these worms exploit before the next wave hits.