Supply Chain Security in the Age of AI: From Surgical Attacks to Automated Cascades
Supply chain attacks have evolved from patient, targeted exploits to fast, automated campaigns leveraging AI-driven dependency management and self-propagating malware. Recent incidents like the Axios and TeamPCP attacks demonstrate how compromised packages can cascade across entire ecosystems in days, while AI coding tools simultaneously increase both developer productivity and attack surface vulnerability.
Metrics in this report
50%
higher for AI agents
117,000+ dependency changes analyzed
2920days
reduction from years to
supply chain attack duration (2 years to 8 days)
43%
of hallucinated packages
appearing repeatedly across queries
2-4multiplier
range
code generation speed improvement
30,000downloads
in weeks
single commonly hallucinated package name
5platforms
cascading impact
TeamPCP campaign (GitHub, npm, PyPI, Docker, VS Code)
20%
proportion of recommendations
LLM package suggestions
1,100packages
average
typical production application
66packages
minimum
npm ecosystem
282packages
before code development
minimal Next.js setup
755packages
median
GitHub JavaScript projects
100,000,000downloads
weekly average
most popular HTTP library on npm