Quick Facts
- Malicious open-source package detections rose 1,444% from 2024 to 2025, according to the Open Source Security Foundation.
- The first half of 2026 alone produced 4.5 times the malicious package volume of all of 2025.
- A software supply chain compromise takes an average of 267 days to identify and contain, the longest breach lifecycle IBM tracks.
Attackers are moving upstream. Instead of targeting finished applications, they are hitting the systems that build and distribute code: CI/CD pipelines, package registries, GitHub Actions workflows, and AI agent tooling. The economics behind this shift are changing fast, and AI is the reason.
AI lets low-skill attackers write working malware, generate variants that evade signature detection, and flood registries with malicious packages at scale. The result is a threat environment that looks nothing like it did two years ago.
The Numbers Are Stark
Throughout 2025, Sonatype identified more than 454,600 new malicious packages, bringing the cumulative total across npm, PyPI, Maven Central, NuGet, and Hugging Face to over 1.233 million. JFrog tracked 11.7 million new packages entering enterprise supply chains in 2025, a 67% increase year over year. Malicious npm package activity alone surged 451%.
The acceleration into 2026 is sharper still. All of 2025 produced 14 attack campaigns and 111 indexed malicious packages. The first half of 2026 produced 37 campaigns and 497 packages. May 2026 was the single busiest month on record: 14 campaigns and 346 packages in 31 days, more than the four preceding months combined.
The Cost Equation Has Flipped
Quincy Castro, CISO at Chainguard, put it plainly. “For 20-plus years, all of the ways we think about handling vulnerabilities grew up around the assumption that exploiting them was expensive,” he said. “AI has completely flipped that dynamic. We’re looking at a world about to be deluged by novel zero-day vulnerabilities, and potentially new classes of vulnerabilities that human beings haven’t been able to discover before. Zero-days are much more of a commodity now.”
Castro also noted that attackers are following the path of least resistance. “As we’ve gotten better at defending traditional endpoints and cloud environments, we’ve naturally pushed adversaries toward a far less defended area,” he said. “Software development is the soft underbelly of organizations.”
Adam Meyers, head of counter adversary operations at CrowdStrike, described the speed problem: “Exploitation windows have collapsed down to hours, and zero-day and n-day vulnerabilities are being weaponized faster than traditional patching cycles can keep up.”
The ‘One-to-Many’ Problem
What makes supply chain attacks attractive is reach. A single compromised package can hit tens of thousands of organizations downstream. Novee Security describes the dynamic: one compromised workflow in one repository can ripple outward into banks, cloud accounts, AI labs, and end-user devices.
About 48,000 common vulnerabilities and exposures were published in 2025, a 20% year-over-year increase. The 2025 Verizon Data Breach Investigations Report found that 30% of breaches now involve a third party, double the share reported in prior years.
What It Costs When Defenses Fail
The IBM Cost of a Data Breach Report 2025 puts the global average breach cost at $4.44 million. In the United States, that figure hits $10.22 million. Supply chain compromises carry an additional burden: they take 267 days on average to identify and contain, the longest lifecycle IBM tracks across all breach types.
IBM research also found that supply chain compromise accounts for 30% of incidents involving AI models and applications. As software teams build more AI-assisted development pipelines, the attack surface grows with them.
Regulatory and Board Pressure Rising
Greg Hughes, CEO of Black Duck, said software supply chain security has become a board-level priority. “Driven by regulations like the EU Cyber Resilience Act and the transformative impact of AI on software development and vulnerability discovery,” he said, companies can no longer treat this as a back-office concern.
Yoav Landman, CTO and co-founder of JFrog, framed the challenge directly: “AI has not only changed how software is written; it has also increased the speed and scale at which zero-day vulnerabilities are exploited, and malicious software supply chain attacks are developed and distributed.”
For software and technology executives, the message is clear. The tools attackers use have improved faster than most enterprise defenses. The registries your engineers depend on daily are now high-value targets, and the window to detect a compromise is measured in months, not days.
Read more: AI is changing the economics of software supply chain attacks
