Research from Sonatype and Forrester examines how AI is driving precision software supply chain attacks - and what this means for software governance, enterprise resilience, and responsible AI adoption across highly regulated industries.HYDERABAD, India , July 29, 2026 /PRNewswire/ -- Sonatype®, the company helping enterprises accelerate agentic software development with confidence, is bringing together technology, cybersecurity, and business leaders in India in association with Forrester to examine how artificial intelligence is reshaping software supply chain risk - and what enterprises must do to respond.The discussion is informed by Sonatype's latest research, The Trust Economy of Software: How AI is Reshaping Software Supply Chain Risk for Financial Services. Based on an analysis of 9,747 verified malicious package advisories between January 2020 and May 2026, along with enterprise telemetry from the financial services sector, the study reveals a fundamental change in attacker behaviour.Software supply chain attacks are no longer driven primarily by scale. Attackers are increasingly using precision campaigns designed to impersonate trusted software, target developers, and influence component-selection decisions before code reaches production. The implications are especially significant for India, one of the world's fastest-growing software development hubs and a global centre for financial technology, digital engineering, and Global Capability Centres. As Indian enterprises and GCCs expand their use of open-source software, third-party components, and AI-assisted development, the ability to govern what enters the software lifecycle is becoming a strategic business priority."AI is helping development teams assemble software faster, but it is also accelerating the number of decisions they make about what software to trust. Attackers understand that shift. They are no longer relying only on scale; they are investing in precision attacks that look familiar, targeting developers directly, and executing before traditional controls have a chance to intervene. For Indian enterprises and GCCs, the priority is not to slow AI adoption. It is to establish trusted governance at the point where software enters development," said Abhishek Chauhan, Senior Director of Technology and India Country Head, Sonatype.Sonatype's research found:
Sonatype and Forrester Address the Growing AI-Era Software Supply Chain Risk Facing Indian Enterprises in the Guru Forum
Sonatype and Forrester Address the Growing AI-Era Software Supply Chain Risk Facing Indian Enterprises in the Guru Forum
Malicious package attacks jumped 75-fold (2023-25); 47% impersonate trusted software to target developers before controls activate. Governance must shift left—establish trust at component selection, not after—to defend against precision attacks in AI-driven development.








