Skip to main content

Cybersecurity statistics / npm Package

Malicious npm packages surged 451% year-over-year.

PublisherJFrog
Report2026 Software Supply Chain Security State of the Union
Published20 May 2026
Topicsnpm Package, Package Management, Malicious Package

Published by JFrog in 2026 Software Supply Chain Security State of the Union, 20 May 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

The "Qix" campaign used 25 packages to compromise over 2.5 million downloads.
JFrog, 27/05/2026
177,000 new malicious packages were detected across registries in the last year.
JFrog, 27/05/2026
495 malicious AI models were identified on Hugging Face.
JFrog, 27/05/2026
18% of organizations have zero governance over their IDE or MCP servers inside developers' workflows.
JFrog, 27/05/2026
97% of organizations claim they have certified model governance.
JFrog, 27/05/2026
Secrets detection is active at just 28% of organizations.
JFrog, 27/05/2026

Get the newsletter

Weekly cybersecurity statistics by email.