Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 22, 2026 (about 3 months ago).

people · May 22, 2026

JFrog Report Shows npm Attacks Surged 451% in 2025

Share the canonical public link.

Share as image

The New Stack covered JFrog's 2026 report findings released around May 20-22, 2026, highlighting a 451% surge in malicious npm packages and 495 malicious AI models discovered. The analysis drew from JFrog platform data and responses from over 1,500 security and DevOps professionals. 97% of enterprises claimed strong AI governance, yet 1 in 5 had no real enforcement and 53% pulled models from public registries. JFrog positioned AI as now constituting the core of the software supply chain rather than an add-on.

Below validation threshold — auto-passed without scoring

Supporting evidence