Leading software security firm JFrog has released its 2026 Software Supply Chain Security State of the Union report, revealing:

Enterprise Software Risk is Accelerating at an Unprecedented Rate

Threat actors are now expanding their activities beyond traditional package registries to target AI model registries and developer tooling.

The report highlights that attackers are actively weaponising the trusted models and developer workflows that drive modern, AI-powered development. This shift has created a significant blind spot within current software governance frameworks.

CEO and Co-Founder of JFrog, Shlomi Ben Haim, stated that adding AI to the software supply chain has increased the attack surface for malicious actors. He noted that the era of “scan and hope” is over, and organisations now require a single source of truth to govern every binary, model, and AI agent from entry to production.

Record Increase in Malicious Packages

The data shows that malicious npm packages have surged by 451% year-on-year. In total, 177,000 new malicious packages were detected across various registries over the past twelve months. Attackers are exploiting trust at a massive scale; for instance, the “Qix” campaign employed just 25 packages to compromise over 2.5 million downloads. This demonstrates how effectively a small number of malicious assets can infiltrate the global software ecosystem.

Emergence of AI Agent Attacks

For the first time, JFrog has tracked malicious AI agent skills, identifying 969 that carry high-impact payloads. Additionally, researchers found 495 malicious AI models on Hugging Face and 56 malicious extensions on OpenVSX. These findings indicate that attackers are no longer solely targeting code, but are instead focusing on the autonomous tools used to write, review, and deploy software. This represents a significant shift in the methodology of supply chain incursions.

Flaws in Vulnerability Reporting

The report reveals that over 48,000 new Common Vulnerabilities and Exposures (CVEs) were disclosed in 2025, marking a 20% year-on-year increase. This rise is partially attributed to AI-generated code reintroducing historical weaknesses. For example, Injection (CWE-74) incidents grew by 3,110%. However, the JFrog Security Research team found that 66% of the CVEs analysed had minimal real-world applicability.

This suggests that volume-based triage creates unnecessary noise, whereas context is vital for effective security.

The Governance Gap

Despite 97% of organisations claiming to have certified model governance, a significant disparity exists between perceived and actual security. The report found that 53% of organisations self-host models from sources where malicious payloads have been detected. Furthermore, 18% have no governance over their integrated development environments (IDE) or Model Context Protocol (MCP) servers.

Currently, only 40% of organisations have adopted malicious package detection, and secrets detection is active at only 28%. This highlights that the fastest-growing threats remain the least defended by existing tooling. Security teams are also facing a mounting human cost, with 45% of respondents reporting that reviewing AI-generated code is a major time drain.

VP of JFrog Security Research, Shachar Menashe, warned that the industry is operating with a false sense of security. He argued that moving to automated, platform-native governance is now essential to secure intelligent systems.

AI has increased the speed at which zero-day vulnerabilities are exploited, emphasisng the challemges thts organisations must address to fortify their supply chains at scale to maintain security.

JFrog       Image: Ideogram

Source:  Cyber Security Intelligence