product · May 22, 2026
JFrog Releases 2026 Software Supply Chain Security State of the Union Report
Share the canonical public link.
JFrog released its 2026 Software Supply Chain Security State of the Union report on or around May 20, 2026. The report, based on threat intelligence from the JFrog Security Research team, platform data, and a survey of over 1,500 professionals across eight countries, found new packages entering supply chains up 67% year-over-year to an unspecified total, 177,000 new malicious packages uncovered in 2025, and npm attacks surging 451%. It also identified 495 malicious AI models and noted that 97% of organizations claim AI governance while 53% pull models from public registries and only 40% have detection tools in place. JFrog Security Research analyzed specific incidents including the May 19 Shai-Hulud wave compromising npm and PyPI packages with credential theft and worm-like propagation.