AI Coding Agents Expand Software Supply Chain Risks

AI Coding Agents Expand Software Supply Chain Risks

First seen 27 Jul 2026, 22:48 UTC AugmentcodeSonatypewww.endorlabs.comAicerts.AiBleepingcomputer+2 80% similarity 71.8

Article Content

Browse articles
ThreatCluster

AI coding agents are introducing significant vulnerabilities into the software supply chain by selecting insecure dependencies without human oversight. Research indicates that only 20% of dependency versions recommended by these agents are safe, leading to a surge in malicious packages. In 2025, over 454,600 new malicious packages were reported, marking a 75% increase from the previous year. The Verizon 2026 DBIR revealed that third-party involvement in breaches rose to 48%, up from 30% in 2025. Organizations are advised to treat AI-generated code as untrusted and enforce rigorous security controls. The shift in dependency governance necessitates new security measures that account for AI's role in software development. As AI assets become critical, traditional security practices may not suffice to manage the evolving threat landscape.

Key Points: • Only 20% of AI-recommended dependencies are safe, increasing supply chain risks. • In 2025, over 454,600 new malicious packages were reported, a 75% increase. • Organizations must treat AI-generated code as untrusted and enforce strict security controls.

ThreatCluster AI How this analysis works

Timeline

2025-08-01
CVE-2025-54136 published
A critical vulnerability was disclosed, impacting software supply chain security.
Augmentcode
2026-01-15
First public PoC for CVE-2025-54136
A proof of concept was released, demonstrating exploitation of the vulnerability.
Augmentcode
2026-07-27
Endor Labs report on AI coding agents
Endor Labs revealed that AI coding agents are importing vulnerable dependencies at scale.
Endor Labs
2026-07-28
Sonatype report on AI in software supply chain
Sonatype highlighted the need for security leaders to rethink governance due to AI dependencies.
Sonatype

Community

Browse all →

Tracked Entities in This Story