Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 21, 2026 (about 3 months ago).

people · May 21, 2026

JFrog Releases 2026 Software Supply Chain Security State of the Union Report

Share the canonical public link.

Share as image

JFrog Ltd. announced the findings of its 2026 Software Supply Chain Security State of the Union report on May 20, 2026. The report draws on data from 18.2 billion artifacts managed across the JFrog Platform, which grew 136% year-over-year, a global survey of 1,508 security and DevOps professionals, and original research by the JFrog Security Research team. Key findings include a 451% year-over-year surge in malicious npm packages reaching 177K new detections, 495 malicious AI models on Hugging Face, and 969 malicious AI agent skills identified. JFrog CTO and Co-Founder Yoav Landman stated that AI has increased the speed and scale at which zero-day vulnerabilities are exploited and malicious supply chain attacks are developed and distributed. The report also notes that 97% of organizations claim certified model governance while 53% self-host models from sources with detected malicious payloads.

Below validation threshold — auto-passed without scoring

Supporting evidence