- JFrog's 2026 Software Supply Chain Security State of the Union reports a 451% surge in malicious packages year over year, reaching over 171,000 unique instances.
- JFrog has announced new solutions integrated with Zscaler, Cloudflare, and Netskope to stop malicious packages at the network level before they reach users' machines.
- JFrog Traffic Controller is available immediately through JFrog Curation, supporting Zscaler Internet Access, Cloudflare Gateway, and Netskope One SSE.
- Only 40% of organizations have malicious package detection capabilities in place, and secrets detection is active in just 28% of enterprises.
- AI coding agents like Claude Code, Cursor, Copilot, and Kiro now run directly on developer machines, autonomously pulling dependencies and installing libraries.
- Gartner recognized software supply chains as one of four critical and unpredictable threats where attackers hold a significant advantage.
JFrog's Traffic Controller is designed to combat the alarming rise in malicious software packages, which surged by 451% in the past year, reaching over 171,000 unique instances. This solution integrates with leading SASE providers like Zscaler, Cloudflare, and Netskope to ensure that all software package downloads are routed through JFrog Artifactory, the single source of truth for software artifacts.
The Traffic Controller not only blocks malicious packages but also allows compliant packages to flow seamlessly, ensuring that developers and AI agents can continue their work without disruption. Shlomi Ben Haim, JFrog's Co-Founder and CEO, emphasized the need for organizations to have control over their software supply chains, stating, “Open source has powered software innovation for decades, but in today’s zero-trust world, simply enabling traffic is no longer enough.”

The solution is particularly timely as the window for exploiting vulnerabilities has shrunk to mere hours, making it critical for organizations to have comprehensive visibility into their software components. Gartner has identified software supply chains as one of the most significant threats, highlighting the need for robust security measures.
By partnering with top security firms, JFrog aims to create a unified control point for software consumption, ensuring that every package is curated before use. Gal Marder, Chief Strategy Officer at JFrog, noted, “We’re making it possible for the entire software security ecosystem to enforce the same standard with zero friction.” The Traffic Controller is available immediately, with plans for additional SASE partners to follow.
“JFrog's 2026 State of the Union shows a 451% surge in malicious packages to over 171,000 instances, yet only 40% of organizations have detection capabilities. CEO Shlomi Ben Haim says the answer is a universal control point, not another alert or gate.”


/dq/media/media_files/2026/08/29/jfrog-2026-08-29-19-05-37.png)





