Report by JFrog
2026 Software Supply Chain Security State of the Union
Key Findings
495 malicious AI models were identified on Hugging Face.
18% of organizations have zero governance over their IDE or MCP servers inside developers' workflows.
97% of organizations claim they have certified model governance.
Secrets detection is active at just 28% of organizations.
45% of security and DevOps professionals say reviewing and hardening AI-generated code is now a major time drain.
The "Qix" campaign used 25 packages to compromise over 2.5 million downloads.
969 malicious AI agent skills were identified carrying high-impact payloads.
56 malicious extensions were identified on OpenVSX.
Malicious npm packages surged 451% year-over-year.
177,000 new malicious packages were detected across registries in the last year.
Over 48,000 new CVEs were disclosed in 2025, a 20% year-over-year increase.
Injection (CWE-74) occurrences grew 3,110%.
66% of analyzed CVEs had minimal real-world applicability.
Only 40% of organizations have adopted malicious package detection.
53% of organizations self-host models from sources where malicious payloads have been detected.