Hyderabad

AI fuels precision software supply chain attacks, Sonatype and Forrester warn

Artificial intelligence is rapidly transforming the software threat landscape, enabling cybercriminals to launch increasingly sophisticated software supply chain attacks that target developers and enterprise systems, according to a joint report released by Sonatype and Forrester at the Guru Forum in Hyderabad on Tuesday.

Hyderabad: Artificial intelligence is rapidly transforming the software threat landscape, enabling cybercriminals to launch increasingly sophisticated software supply chain attacks that target developers and enterprise systems, according to a joint report released by Sonatype and Forrester at the Guru Forum in Hyderabad on Tuesday.

The report, The Trust Economy of Software: How AI is Reshaping Software Supply Chain Risk for Financial Services, analysed 9,747 verified malicious package advisories recorded between January 2020 and May 2026. It highlights a dramatic rise in precision attacks designed to compromise software during the development stage, before it reaches production environments.

According to the findings, targeted malicious package advisories surged 75-fold—from just 28 cases in 2023 to 1,576 in 2025. Nearly 47% of the malicious packages impersonated trusted software, while 53% specifically targeted developers during software installation. More than one in four malicious packages also used advanced techniques such as code obfuscation, multi-stage droppers and hidden backdoors to evade detection.

Abhishek Chauhan, Senior Director of Technology and India Country Head at Sonatype, said AI is accelerating software development but is also increasing the number of trust decisions developers must make. He emphasised that organisations should strengthen governance at the point where software enters the development lifecycle rather than slowing the adoption of AI.

Ashutosh Sharma, Vice President and Principal Analyst at Forrester, noted that AI is reshaping how software components are discovered, selected and integrated, making software governance and supply chain trust essential for organisations seeking to balance innovation with cyber resilience.

The report also cautioned that India’s fast-growing financial technology sector and Global Capability Centres (GCCs) need stronger software governance frameworks as open-source software, third-party components and AI-assisted development become increasingly central to digital transformation initiatives.

For more details: Munsif daily.com

Related Stories

Mohammed Yousuf Qasmi

Senior Content Editor – Hyderabad & Telangana Affairs!Mohammed Yousuf is a Senior Content Editor at Munsif News 24x7, covering Hyderabad and Telangana affairs.With over a decade of experience in journalism, Yousuf reports on governance, public issues, law and order, and political developments.He regularly contributes breaking news and in-depth reports to Munsif News 24x7.
Back to top button