Software Supply Chain Attacks Hit Records, JFrog Finds — iTech360Hub
Cybersecurity DevSecOps

Software Supply Chain Attacks Hit Records, JFrog Finds — AI Governance Failing as Threats Escalate

iTech360Hub | 6 min read | Research Report

The software security landscape has entered a new era of systemic risk. JFrog Ltd., the Liquid Software company and creators of the JFrog Software Supply Chain Platform, has released the findings of its 2026 Software Supply Chain Security State of the Union report — and the picture it paints is alarming. Threat actors are no longer confining their attacks to traditional package registries. They are actively expanding into AI model registries and developer tooling, exploiting the very workflows that modern software teams depend on.

The report draws on data from 18.2 billion artifacts managed across the JFrog Platform — itself up 136% year-over-year — as well as original vulnerability research by the JFrog Security Research team and a global survey of 1,508 security and DevOps professionals. Together, these sources expose what JFrog calls the "illusion of mastery": a deepening chasm between organizations' perceived security confidence and the actual, mounting risks accumulating in their infrastructure.

As AI moves from an experimental capability to a structural force reshaping how software is created and distributed, organizations are finding themselves increasingly exposed — often without realizing it. The era of passive, scan-and-hope security postures, the report argues, is definitively over.

451%
Year-over-year surge in malicious npm packages
177K
New malicious packages detected across registries
48K+
New CVEs disclosed in 2025, up 20% year-over-year

"Every enterprise is adding AI to their software supply chain, which is increasing the attack surface for bad actors. Our report shows attackers are no longer just breaching traditional defenses – they are actively weaponizing the trusted models, registries, and agentic tools driving today's AI-powered development. The era of 'scan and hope' is over."

— Shlomi Ben Haim, CEO & Co-Founder, JFrog

Malicious Packages Reach an All-Time High

Malicious npm packages surged 451% year-over-year, with 177,000 new malicious packages detected across registries in the past year alone. Attackers are exploiting trust at unprecedented scale. In one striking example, a campaign called "Qix" used just 25 packages to compromise over 2.5 million downloads — demonstrating how efficiently adversaries can weaponize the open-source ecosystem that development teams rely on daily.

AI Agent Skills: The Emerging Attack Surface

For the first time in the report's history, JFrog has tracked malicious AI agent skills as a distinct threat category. Researchers identified 969 such skills carrying high-impact payloads, alongside 495 malicious AI models on Hugging Face and 56 malicious extensions on OpenVSX. The implication is profound: attackers are no longer merely targeting source code. They are targeting the autonomous tools that write, review, and deploy that code.

The report further highlights a stark governance gap: 18% of organizations have zero oversight of IDE plugins or Model Context Protocol (MCP) servers operating inside their developers' daily workflows. These tools sit at the heart of modern AI-assisted development — and they represent an almost entirely unmonitored entry point for adversaries.

The Qix Campaign

A single coordinated attack campaign used just 25 carefully crafted packages to compromise over 2.5 million downloads — illustrating how a minimal footprint can produce catastrophic downstream impact when embedded in widely trusted registries.

AI Model Registry Infiltration

With 495 malicious AI models identified on Hugging Face, attackers have shifted focus to the repositories developers use to pull pre-trained models directly into production pipelines — an attack vector that most security toolchains are not yet equipped to detect.

IDE & MCP Server Blind Spots

With 56 malicious extensions found on OpenVSX and 18% of organizations having no governance over their IDE or MCP servers, the developer environment itself has become a prime target — exploiting the trust developers place in their own local tooling.

CVE Volume Surges — But Severity Scores Are Misleading

Over 48,000 new CVEs were disclosed in 2025, representing a 20% year-over-year increase. Part of this growth is being driven by AI-generated code that inadvertently reintroduces decades-old weaknesses — with Injection vulnerabilities (CWE-74) alone growing by a staggering 3,110%. Yet sheer volume is not the whole story.

JFrog's Security Research team found that 66% of CVEs analyzed had minimal real-world applicability. This means organizations relying on volume-based triage — treating every disclosed vulnerability as equally urgent — are wasting resources on low-risk issues while potentially overlooking the handful of CVEs that present genuine, exploitable danger. Context and applicability, the report argues, are the true mission-critical signals in modern vulnerability management.

"AI has not only changed how software is written; it has also increased the speed and scale at which zero-day vulnerabilities are exploited, and malicious software supply chain attacks are developed and distributed."

— Yoav Landman, CTO & Co-Founder, JFrog

The Fastest-Growing Threats Are the Least Defended

The survey data reveals a troubling inversion: the threat categories growing fastest in volume remain the least covered by existing security tooling. Only 40% of organizations have adopted malicious package detection, and secrets detection is active at a mere 28% of respondents. Meanwhile, 45% of security professionals report that reviewing and hardening AI-generated code has become a significant time burden — evidence that AI tools have not eliminated security workloads but have fundamentally redistributed them. The human cost of AI-assisted development is falling squarely on security teams.

Key Registries & Platforms Referenced
npm Registry Hugging Face OpenVSX JFrog Platform CI/CD Pipelines MCP Servers
Key Takeaways
1
Malicious npm packages surged 451% year-over-year — 177,000 new malicious packages were detected across registries in the past twelve months alone.
2
AI agent skills are now an active attack surface: 969 malicious AI agent skills, 495 malicious AI models on Hugging Face, and 56 malicious IDE extensions on OpenVSX were identified for the first time.
3
CVE volume is misleading: 66% of analyzed CVEs have minimal real-world applicability, even as total disclosures passed 48,000 — context-based triage is now essential.
4
Security tooling coverage remains dangerously low: only 40% of organizations use malicious package detection, and just 28% have active secrets detection in their pipelines.
5
The AI governance gap is widening: 97% of organizations claim certified model governance, yet 53% self-host models from sources where malicious payloads have been actively detected.

The JFrog 2026 report delivers a clear verdict: the software industry is operating under a dangerous illusion of control. The sheer pace at which AI is being integrated into development pipelines is outrunning the governance frameworks meant to secure them. Shachar Menashe, VP of JFrog Security Research, put it plainly — the real threat lies not just in external attackers but in the hijacking of CI/CD pipelines and developer tools at the point where code itself originates. Moving to automated, platform-native governance is no longer a strategic option; it is an operational necessity.

For security leaders, DevOps teams, and engineering executives looking to understand the full scope of today's supply chain risks — and the specific steps required to close these gaps — the complete 2026 Software Supply Chain Security State of the Union report is available directly from JFrog's official website at jfrog.com.

Tags
JFrog Software Supply Chain Cybersecurity DevSecOps AI Security Malicious Packages CVE Management Open Source Risk