Malicious npm packages surged 451% year-over-year.
| Publisher | JFrog |
| Report | 2026 Software Supply Chain Security State of the Union |
| Published | 20 May 2026 |
| Topics | npm Package, Package Management, Malicious Package |
Published by JFrog in 2026 Software Supply Chain Security State of the Union, 20 May 2026. The figure is taken from the report as published; the full methodology is in the source.