How AI Agents Expand the Software Supply Chain Attack Surface
How AI Agents Expand the Software Supply Chain Attack Surface
In his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.
- Sarah Gooding
At AI Council 2026, Socket founder and CEO Feross Aboukhadijeh examined how coding agents are changing the software supply chain threat model. Agents can select dependencies, connect to MCP servers, install skills, and execute code with developer credentials, often without a human reviewing those decisions.
The talk highlights three important developments:
- AI agents increasingly choose, install, and run third-party code.
- Existing security infrastructure assumes humans make those trust decisions.
- That infrastructure is struggling as development moves to machine speed.
Feross walks through several major supply chain attacks from 2026, including incidents involving Axios, TanStack, and Trivy. The examples show how attackers are using compromised maintainers, malicious transitive dependencies, prompt injection, and trusted development tools to reach both developers and their agents. He also covers risks across MCP servers, agent skills, and IDE extensions, along with the strain AI-assisted vulnerability discovery is placing on security teams.
If you’re tired of the AI doomsday takes, watch the full talk below for Feross’ more optimistic view of how these same capabilities are helping defenders analyze open source code, prioritize vulnerabilities, and improve software security over time.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.