JFrog warns of record software supply chain attacks as AI governance gaps widen
JFrog’s 2026 Software Supply Chain Security State of the Union reports a dramatic surge in malicious software packages and new AI‑driven attack vectors. Malicious npm packages rose 451% year‑over‑year to 177,000 new instances, and the company identified 969 malicious AI agent skills, 495 hostile AI models on Hugging Face and dozens of malicious extensions on OpenVSX.
Adoption of essential security controls remains low: only about 40% of organisations use malicious‑package detection and just 28% have active secrets‑detection. The report highlights a stark gap between executive confidence and actual protective measures, with 97% of firms claiming model‑governance certification while many lack practical oversight.
Indian enterprises are especially vulnerable. Sixty‑five percent lack malicious‑package detection and 71% do not employ container security. Indian dev‑ops teams now spend roughly half of their time reviewing AI‑generated code, and a majority distrust code produced by AI tools. These findings underscore a systemic risk across the global software supply chain as AI accelerates development and expands the attack surface.