[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZ1B0ttuyZA6HfOyXExqopwxeYcLJeVmswBoCkpjqBQs":3},{"article":4,"iocs":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"1b06d8cf-0af3-47b4-8c70-9ba5a10a4a0a","How AI Agents Expand the Software Supply Chain Attack Surface","how-ai-agents-expand-the-software-supply-chain-attack-surface-ea0959","At AI Council 2026, Socket founder and CEO Feross Aboukhadijeh examined how coding agents are changing the software supply chain threat model. Agents can select dependencies, connect to MCP servers, install skills, and execute code with developer credentials, often without a human reviewing those decisions. The talk highlights three important developments: AI agents increasingly choose, install, and run third-party code. Existing security infrastructure assumes humans make those trust decisions. That infrastructure is struggling as development moves to machine speed. Feross walks through several major supply chain attacks from 2026, including incidents involving Axios, TanStack, and Trivy. The examples show how attackers are using compromised maintainers, malicious transitive dependencies, prompt injection, and trusted development tools to reach both developers and their agents. He also covers risks across MCP servers, agent skills, and IDE extensions, along with the strain AI-assisted vulnerability discovery is placing on security teams. If you’re tired of the AI doomsday takes, watch the full talk below for Feross’ more optimistic view of how these same capabilities are helping defenders analyze open source code, prioritize vulnerabilities, and improve software security over time.","Feross Aboukhadijeh discussed how AI coding agents are altering the software supply chain threat model. These agents can select, install, and execute third-party code with developer credentials, often bypassing human review. Attackers are exploiting this by using compromised maintainers, malicious dependencies, and prompt injection to target both developers and their AI agents, impacting tools like Axios, TanStack, and Trivy.","AI coding agents are expanding software supply chain attack surface by automating dependency selection and code","Back[Security News]How AI Agents Expand the Software Supply Chain Attack SurfaceIn his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.Sarah GoodingAug 16, 2026|1 min readAt AI Council 2026, Socket founder and CEO Feross Aboukhadijeh examined how coding agents are changing the software supply chain threat model. Agents can select dependencies, connect to MCP servers, install skills, and execute code with developer credentials, often without a human reviewing those decisions.The talk highlights three important developments:AI agents increasingly choose, install, and run third-party code.Existing security infrastructure assumes humans make those trust decisions.That infrastructure is struggling as development moves to machine speed.Feross walks through several major supply chain attacks from 2026, including incidents involving Axios, TanStack, and Trivy. The examples show how attackers are using compromised maintainers, malicious transitive dependencies, prompt injection, and trusted development tools to reach both developers and their agents. He also covers risks across MCP servers, agent skills, and IDE extensions, along with the strain AI-assisted vulnerability discovery is placing on security teams. If you’re tired of the AI doomsday takes, watch the full talk below for Feross’ more optimistic view of how these same capabilities are helping defenders analyze open source code, prioritize vulnerabilities, and improve software security over time.","https:\u002F\u002Fsocket.dev\u002Fblog\u002Fai-agents-supply-chain-attack-surface?utm_medium=feed","https:\u002F\u002Fcdn.sanity.io\u002Fimages\u002Fcgdhsj6q\u002Fproduction\u002F212c7b5ef8dd232ed4925cee51fc5726e0aa0195-1672x941.png?w=1000&q=95&fit=max&auto=format","2026-08-16T21:04:44.337+00:00","2026-08-17T06:00:10.400485+00:00",8,[18,21,23,25,28],{"name":19,"type":20},"Axios","product",{"name":22,"type":20},"TanStack",{"name":24,"type":20},"Trivy",{"name":26,"type":27},"Socket","vendor",{"name":29,"type":30},"AI agents","technology","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":31,"icon":33,"name":34,"slug":35},null,"Supply Chain","supply-chain",[37,39,44,49],{"category":38},{"id":31,"icon":33,"name":34,"slug":35},{"category":40},{"id":41,"icon":33,"name":42,"slug":43},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":45},{"id":46,"icon":33,"name":47,"slug":48},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":50},{"id":51,"icon":33,"name":52,"slug":53},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[55],{"type":56,"value":57,"context":58},"malware","prompt injection","Attack vector used by threat actors"]