IT Brief US - Technology news for CIOs & IT decision-makers
United States
Cloudsmith finds gap in software supply chain defences

Cloudsmith finds gap in software supply chain defences

Wed, 30th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Cloudsmith has published research highlighting a gap between engineering teams' confidence in their software supply chain defences and the steps they take to screen dependencies.

The study surveyed 400 Platform and Security Engineers in the UK and US.

The findings come as attacks on open-source package ecosystems face growing scrutiny across the software industry. Recent incidents cited in the research include attacks linked to npm and PyPI, as well as a disclosed case in which an attacker took over an active AI coding-assistant session and spread the self-propagating Shai-Hulud worm across about 100 internal repositories, while stealing source code and secrets.

According to the research, 73% of engineering teams believe their current tooling can stop an install-time attack before any security advisory is issued. Yet only 38% screen dependencies for threats before those packages enter their systems.

Just 24% automatically enforce a cooldown period on newly released dependencies. Cloudsmith described this as a short window in which many malicious versions are identified and removed.

More than half of respondents, 54%, said they act only after malicious code has already reached their systems. A further 8% have no consistent response at all.

Trust signals

The research also examined how teams decide whether a software dependency can be trusted. Half of respondents said they rely on provenance or attestation data as a trust signal, while 8% said it is their primary signal.

That matters because provenance data shows where a build came from, but does not by itself show whether the resulting package is safe. The study points to recent smaller Shai-Hulud attacks as an example of how malicious code can enter at the build stage while a product still carries a valid SLSA attestation.

The broader backdrop is growing reliance on open-source registries during software development. Modern software depends heavily on public registries, and AI agents are increasing exposure by pulling in dependencies without human review.

In many of the attacks cited, malicious code runs through pre-install scripts. By compromising a trusted account or build pipeline, attackers can make harmful packages appear legitimate at first glance.

Responsibility split

The survey found that responsibility for these decisions is not always clear inside organisations. Some 78% of teams said security is the function most concerned with dependency-led attacks.

When asked where the decision to trust an open-source dependency should sit, 39% said a centralised Security, Platform or Governance team should hold that responsibility. Another 37% said the decision should be shared with developers.

In practice, however, developers often end up making those decisions under time pressure. That can leave engineering teams exposed when package choices are made quickly, with limited information beyond registry metadata and build-origin records.

Cloudsmith's findings arrive amid a series of supply-chain incidents that have raised questions about whether common trust checks are enough. The disclosed compromise involving an AI coding assistant has added to concerns that automation can widen the path for hostile packages or code changes to spread inside development environments.

While confidence in tooling remains high, the report suggests many organisations still rely on reactive controls rather than blocking risky software before it reaches internal systems. That contrast between stated confidence and operational behaviour is central to the study's conclusions.

Glenn Weinstein, Chief Executive Officer, Cloudsmith, said: "Securing the software supply chain is a team sport. Developers, platform engineering and security teams, and vendors all have important parts to play. We all depend on open source software, so we all need to make it easier to set up developer environments in ways that are secure by default. Maintaining curated private repositories with pre-scanned and approved packages is a great way to do this. It's not a blame game - the survey findings aren't entirely surprising, and they're not any one team's fault. But we need to reduce the burden on developers and make it easier to manage dependencies securely."