Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 4 › IT News › Developer

AI Coding Tools Are Accelerating Dependency Sprawl and Expanding Malware Risk With It

VentureBeat, Thursday, September 24th, 2026

AI coding assistants pull in open-source dependencies faster than security teams can vet them, VentureBeat reports.

VentureBeat reports AI coding assistants are pulling open-source dependencies into enterprise systems faster than security teams can vet them, creating supply chain risk; Chainguard's CISO notes 'velocity has outpaced governance and controls.'

Attackers increasingly target lesser-maintained projects rather than popular ones, using typosquatting and maintainer account takeovers to spread malware.

Chainguard research found 97% of known vulnerabilities exist outside the top 20 container images, so security effort concentrates on a small slice of real risk.

Transitive dependencies hide malicious code multiple layers deep, and the piece argues traditional scanning can't scale, pushing toward secure-by-default components with verified provenance.

more →  ·  More from Developer →