Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 21, 2026 (about 3 months ago).

product · May 21, 2026

JFrog Releases 2026 Software Supply Chain Security Report on AI Governance Failures

Share the canonical public link.

Share as image

JFrog published its 2026 Software Supply Chain Security report on May 20, 2026. The report documents 177,000 new malicious packages, 495 malicious AI models, and a 451% increase in infected npm packages. It details how threat actors weaponize developer workflows and AI governance gaps. JFrog Security Research identified over 170 compromised npm packages and related PyPI issues in the ongoing Shai Hulud campaign on May 19, 2026.

Below validation threshold — auto-passed without scoring

Supporting evidence