Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left
Back to News

AI coding tools increase dependency sprawl, raising malware risks for developers

AI coding tools are significantly increasing software dependency sprawl, with 38% of new dependencies containing known security flaws. This trend raises malware risks as developers often accept unverโ€ฆ

AI coding tools are accelerating dependency sprawl and expanding malware risk with it
VentureBeat โ€” 24 September 2026
Text:
3 0 0

AI coding assistants are speeding up the growth of software dependencies and widening the attack surface for malware, a new analysis by security firm Chainguard found. The report, released Tuesday, says developers using tools such as GitHub Copilot, Tabnine and other largeโ€‘languageโ€‘model based generators are adding twice as many thirdโ€‘party libraries to projects as they did a year ago. The surge in automatically suggested code is creating a sprawling โ€œdependency sprawlโ€ that security teams struggle to track.

The trend reflects a broader shift in software development. Since 2022, AI pair programmers have become mainstream, promising faster code writing and fewer bugs. At the same time, openโ€‘source libraries have multiplied, and many contain known vulnerabilities. Supplyโ€‘chain attacks like the 2021 SolarWinds breach have made firms more wary of hidden risks, but the convenience of AI suggestions often outweighs caution. Developers accept generated snippets without fully vetting the underlying packages, leading to a cascade of unverified components in production code.

Chainguardโ€™s data shows that 38โ€ฏpercent of new dependencies introduced by AIโ€‘generated code have at least one known security flaw, and 12โ€ฏpercent are linked to previously identified malware. In one case, a popular AI tool suggested a snippet that pulled in a library with a backdoor, allowing remote code execution on vulnerable servers. Security researchers say the problem is compounded by the โ€œblackโ€‘boxโ€ nature of the models, which can surface code from compromised repositories without warning. Industry groups are calling for stronger software bill of materials (SBOM) practices and for AI providers to audit the code they suggest.

The report urges developers to treat AIโ€‘generated code as untrusted input, subject to the same review as any thirdโ€‘party library. Chainguard recommends integrating automated dependency scanning into CI pipelines and using provenance data to verify the origin of suggested packages. Some AI tool vendors have pledged to add vulnerability checks before offering code, but experts warn that regulatory guidance may be needed to enforce consistent standards. As AI coding assistants become more entrenched, the balance between productivity and security will shape the next wave of software supplyโ€‘chain defenses.

Read Full Story at VentureBeat โ†’
Advertisement
React:
Sources
Sponsored

More to Read

Swiss AI detects natural disaster signs faster than traditiโ€ฆ
๐Ÿ’ป Technology
Swiss AI detects natural disaster signs faster than traditional methods
France 24 ยท 13 days ago
Wardogs, Valheim 1.0 and other new indie games worth checkiโ€ฆ
๐Ÿ’ป Technology
Wardogs, Valheim 1.0 and other new indie games worth checking out
Engadget ยท 13 days ago
UK government rejects 'kill switch' idea for dangerous AI
๐Ÿ’ป Technology
UK government rejects 'kill switch' idea for dangerous AI
BBC Technology ยท 14 days ago
Giant caves beneath sinkhole reveal origin of mystery trencโ€ฆ
๐Ÿ”ฌ Science
Giant caves beneath sinkhole reveal origin of mystery trenches that score Australia's Nulโ€ฆ
Live Science ยท 3 days ago
How to get started with Meta's new AI agent, Muse
๐Ÿ’ป Technology
How to get started with Meta's new AI agent, Muse
Engadget ยท 13 days ago
Declassified documents show UK aware of Israeli war crimes โ€ฆ
๐ŸŒ World News
Declassified documents show UK aware of Israeli war crimes for 24 years
Al Jazeera ยท 14 days ago
Full view