product · May 21, 2026
JFrog Releases 2026 Software Supply Chain Security Report on AI Governance Failures
Share the canonical public link.
JFrog published its 2026 Software Supply Chain Security report on May 20, 2026. The report documents 177,000 new malicious packages, 495 malicious AI models, and a 451% increase in infected npm packages. It details how threat actors weaponize developer workflows and AI governance gaps. JFrog Security Research identified over 170 compromised npm packages and related PyPI issues in the ongoing Shai Hulud campaign on May 19, 2026.
Below validation threshold — auto-passed without scoring