Technology
New JFrog Report Warns: AI Governance Fails as Software Supply Chain Attacks Hit Record Highs
SUNNYVALE, Calif., May 20, 2026--JFrog delivers its 2026 Software Supply Chain Security State of the Union report, which details the hidden costs of AI at scale.
About this update from Jfrog Ltd.
The Hidden Costs of AI at Scale: JFrog’s 2026 Software Supply Chain Security report shows threat actors weaponizing developer workflows, driving 177K new malicious packages, 495 malicious AI models, and a 451% increase in infected npm packages SUNNYVALE, Calif., May 20, 2026--(BUSINESS WIRE)--JFrog Ltd. (Nasdaq: FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, the system of record for trusted software artifacts, binaries, and AI assets today announced the findings of its 2026 Software Supply Chain Security State of the Union report. This year’s report reveals an unprecedented acceleration in enterprise software risk as threat actors expand strikes beyond traditional package registries into AI model registries and developer tooling, creating a blind spot in current software governance frameworks. "Every enterprise is adding AI to their software supply chain, which is increasing the attack surface for bad actors. Our report shows attackers are no longer just breaching traditional defenses – they are actively weaponizing the trusted models, registries, and agentic tools driving today's AI-powered development. The era of 'scan and hope' is over," said Shlomi Ben Haim, CEO & Co-Founder, JFrog. "Organizations need a single source of truth that governs every binary, every model, and every AI agent skill from the moment it enters the pipeline to the moment it is deployed in production. This is what JFrog was built to deliver." As AI moves from experimentation to a structural force reshaping the software supply chain, organizations are seeing a widening gap between reported security confidence and the risks accumulating in their infrastructure. Drawing on data from 18.2 billion artifacts managed across the JFrog Platform (up 136% year‑over‑year), original vulnerability research by the JFrog Security Research team, and a global survey of 1,508 security and DevOps professionals 1, this report exposes what it calls the "illusion of mastery", i.e. the growing disparity between perceived security and the reality of mounting supply chain risk. Key Findings Include: "The industry is operating with a false sense of security. Vulnerabilities are growing in number, but the real threat lies in threat actors hijacking our CI/CD pipelines and developer tools before code even exists,&...