JFrog Report Shows npm Attacks Surged 451% in 2025
Below validation threshold — auto-passed without scoring
The New Stack covered JFrog's 2026 report findings released around May 20-22, 2026, highlighting a 451% surge in malicious npm packages and 495 malicious AI models discovered. The analysis drew from JFrog platform data and responses from over 1,500 security and DevOps professionals. 97% of enterprises claimed strong AI governance, yet 1 in 5 had no real enforcement and 53% pulled models from public registries. JFrog positioned AI as now constituting the core of the software supply chain rather than an add-on.